<?xml version='1.0' encoding='UTF-8'?>
<nvd xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://nvd.nist.gov/feeds/cve/1.2" nvd_xml_version="1.2" pub_date="2013-05-25" xsi:schemaLocation="http://nvd.nist.gov/feeds/cve/1.2 http://nvd.nist.gov/schema/nvdcve.xsd">
  <entry type="CVE" severity="High" seq="2006-0001" published="2006-09-12" name="CVE-2006-0001" modified="2011-03-07" discovered="2005-08-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Microsoft Publisher 2000 through 2003 allows user-assisted remote attackers to execute arbitrary code via a crafted PUB file, which causes an overflow when parsing fonts.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-255A.html" source="CERT">TA06-255A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/406236" source="CERT-VN">VU#406236</ref>
      <ref url="http://www.securityfocus.com/bid/19951" source="BID" patch="1">19951</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/445824/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20060912 Computer Terrorism (UK) :: Incident Response Centre - Microsoft Publisher Font Parsing Vulnerability</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS06-054.mspx" source="MS" patch="1">MS06-054</ref>
      <ref url="http://www.computerterrorism.com/research/ct12-09-2006-2.htm" source="MISC" patch="1" adv="1">http://www.computerterrorism.com/research/ct12-09-2006-2.htm</ref>
      <ref url="http://secunia.com/advisories/21863" source="SECUNIA" patch="1" adv="1">21863</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/28648" source="XF">publisher-pub-code-execution(28648)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3565" source="VUPEN">ADV-2006-3565</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446630/100/100/threaded" source="HP">SSRT061187</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446630/100/100/threaded" source="HP">HPSBST02134</ref>
      <ref url="http://securitytracker.com/id?1016825" source="SECTRACK">1016825</ref>
      <ref url="http://securityreason.com/securityalert/1548" source="SREASON">1548</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:590" source="OVAL" sig="1">oval:org.mitre.oval:def:590</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2000" edition="sp3"/>
        <vers num="2003" edition="sp1"/>
        <vers num="2003" edition="sp2"/>
        <vers num="xp" edition="sp3"/>
      </prod>
      <prod vendor="microsoft" name="publisher">
        <vers num="2000"/>
        <vers num="2002"/>
        <vers num="2003"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0002" published="2006-01-10" name="CVE-2006-0002" modified="2011-04-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment, related to message length validation.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-010A.html" source="CERT" patch="1" adv="1">TA06-010A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/252146" source="CERT-VN" adv="1">VU#252146</ref>
      <ref url="http://www.securityfocus.com/bid/16197" source="BID" patch="1">16197</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421520/100/0/threaded" source="BUGTRAQ" patch="1">20060110 Microsoft Outlook Critical Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421518/100/0/threaded" source="BUGTRAQ" patch="1">20060110 Microsoft Exchange Critical Vulnerability</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-003.mspx" source="MS" patch="1" adv="1">MS06-003</ref>
      <ref url="http://securitytracker.com/id?1015461" source="SECTRACK" patch="1">1015461</ref>
      <ref url="http://securitytracker.com/id?1015460" source="SECTRACK" patch="1">1015460</ref>
      <ref url="http://secunia.com/advisories/18368" source="SECUNIA" patch="1" adv="1">18368</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/22878" source="XF">win-tnef-overflow(22878)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0119" source="VUPEN" adv="1">ADV-2006-0119</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-004.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-004.htm</ref>
      <ref url="http://securityreason.com/securityalert/331" source="SREASON">331</ref>
      <ref url="http://securityreason.com/securityalert/330" source="SREASON">330</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:624" source="OVAL" sig="1">oval:org.mitre.oval:def:624</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1485" source="OVAL" sig="1">oval:org.mitre.oval:def:1485</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1456" source="OVAL" sig="1">oval:org.mitre.oval:def:1456</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1316" source="OVAL" sig="1">oval:org.mitre.oval:def:1316</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1165" source="OVAL" sig="1">oval:org.mitre.oval:def:1165</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1082" source="OVAL" sig="1">oval:org.mitre.oval:def:1082</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="exchange_server">
        <vers num="2000" edition="sp3"/>
        <vers num="5.0" edition="sp1"/>
        <vers num="5.0" edition="sp2"/>
        <vers num="5.5" edition="sp1"/>
        <vers num="5.5" edition="sp2"/>
        <vers num="5.5" edition="sp3"/>
        <vers num="5.5" edition="sp4"/>
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2000" edition="sp3"/>
        <vers num="2003" edition="sp1"/>
        <vers num="2003" edition="sp2"/>
        <vers num="xp" edition="sp3"/>
      </prod>
      <prod vendor="microsoft" name="outlook">
        <vers num="2000" edition="sp3"/>
        <vers num="2002" edition="sp3"/>
        <vers num="2003"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0003" published="2006-04-11" name="CVE-2006-0003" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in the RDS.Dataspace ActiveX control, which is contained in ActiveX Data Objects (ADO) and distributed in Microsoft Data Access Components (MDAC) 2.7 and 2.8, allows remote attackers to execute arbitrary code via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-101A.html" source="CERT" adv="1">TA06-101A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/234812" source="CERT-VN" adv="1">VU#234812</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-014.mspx" source="MS" patch="1" adv="1">MS06-014</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/29915" source="XF">ie-wscriptshell-command-execution(29915)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25006" source="XF">mdac-rdsdataspace-execute-code(25006)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2452" source="VUPEN">ADV-2006-2452</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1319" source="VUPEN">ADV-2006-1319</ref>
      <ref url="http://www.securityfocus.com/data/vulnerabilities/exploits/0day_ie.pdf" source="MISC">http://www.securityfocus.com/data/vulnerabilities/exploits/0day_ie.pdf</ref>
      <ref url="http://www.securityfocus.com/bid/20797" source="BID">20797</ref>
      <ref url="http://www.securityfocus.com/bid/17462" source="BID">17462</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/487219/100/200/threaded" source="BUGTRAQ">20080128 Re: Exploit in IE6,7</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/487216/100/200/threaded" source="BUGTRAQ">20080128 Exploit in IE6,7</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/475490/100/100/threaded" source="BUGTRAQ">20070731 Re: Exploit In Internet Explorer</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/475118/100/100/threaded" source="BUGTRAQ">20070730 RE: Exploit In Internet Explorer</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/475108/100/100/threaded" source="BUGTRAQ">20070730 Re: Exploit In Internet Explorer</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/475104/100/100/threaded" source="BUGTRAQ">20070729 Exploit In Internet Explorer</ref>
      <ref url="http://www.osvdb.org/24517" source="OSVDB">24517</ref>
      <ref url="http://www.milw0rm.com/exploits/2164" source="MILW0RM">2164</ref>
      <ref url="http://www.milw0rm.com/exploits/2052" source="MILW0RM">2052</ref>
      <ref url="http://www.hitachi-support.com/security_e/vuls_e/HS06-013_e/index-e.html" source="CONFIRM">http://www.hitachi-support.com/security_e/vuls_e/HS06-013_e/index-e.html</ref>
      <ref url="http://www.hitachi-support.com/security_e/vuls_e/HS06-013_e/01-e.html" source="CONFIRM">http://www.hitachi-support.com/security_e/vuls_e/HS06-013_e/01-e.html</ref>
      <ref url="http://securitytracker.com/id?1015894" source="SECTRACK">1015894</ref>
      <ref url="http://secunia.com/advisories/20719" source="SECUNIA">20719</ref>
      <ref url="http://secunia.com/advisories/19583" source="SECUNIA" adv="1">19583</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1778" source="OVAL" sig="1">oval:org.mitre.oval:def:1778</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1742" source="OVAL" sig="1">oval:org.mitre.oval:def:1742</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1511" source="OVAL" sig="1">oval:org.mitre.oval:def:1511</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1323" source="OVAL" sig="1">oval:org.mitre.oval:def:1323</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1204" source="OVAL" sig="1">oval:org.mitre.oval:def:1204</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="data_access_components">
        <vers num="2.5" edition="sp3"/>
        <vers num="2.7" edition="sp1"/>
        <vers num="2.8" edition="sp1"/>
        <vers num="2.8" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0004" published="2006-02-14" name="CVE-2006-0004" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft PowerPoint 2000 in Office 2000 SP3 has an interaction with Internet Explorer that allows remote attackers to obtain sensitive information via a PowerPoint presentation that attempts to access objects in the Temporary Internet Files Folder (TIFF).</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <env/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/963628" source="CERT-VN">VU#963628</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-010.mspx" source="MS" patch="1" adv="1">MS06-010</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0579" source="VUPEN">ADV-2006-0579</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24490" source="XF">powerpoint-tiff-information-disclosure(24490)</ref>
      <ref url="http://www.securityfocus.com/bid/16634" source="BID">16634</ref>
      <ref url="http://securitytracker.com/id?1015632" source="SECTRACK">1015632</ref>
      <ref url="http://secunia.com/advisories/18865" source="SECUNIA">18865</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1555" source="OVAL" sig="1">oval:org.mitre.oval:def:1555</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2000" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0005" published="2006-02-14" name="CVE-2006-0005" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in the plug-in for Microsoft Windows Media Player (WMP) 9 and 10, when used in browsers other than Internet Explorer and set as the default application to handle media files, allows remote attackers to execute arbitrary code via HTML with an EMBED element containing a long src attribute.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-045A.html" source="CERT">TA06-045A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/692060" source="CERT-VN">VU#692060</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24493" source="XF">win-mediaplayer-plugin-embed-bo(24493)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0575" source="VUPEN">ADV-2006-0575</ref>
      <ref url="http://www.securityfocus.com/bid/16644" source="BID">16644</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-006.mspx" source="MS">MS06-006</ref>
      <ref url="http://www.idefense.com/intelligence/vulnerabilities/display.php?id=393" source="IDEFENSE">20060214 Microsoft Windows Media Player Plugin Buffer Overflow Vulnerability</ref>
      <ref url="http://securitytracker.com/id?1015628" source="SECTRACK">1015628</ref>
      <ref url="http://secunia.com/advisories/18852" source="SECUNIA" adv="1">18852</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1559" source="OVAL" sig="1">oval:org.mitre.oval:def:1559</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows-nt">
        <vers num="2000"/>
        <vers num="datacenter_server" edition="sp1"/>
        <vers num="datacenter_server" edition="sp2"/>
        <vers num="datacenter_server" edition="sp3"/>
        <vers num="datacenter_server" edition="sp4"/>
        <vers num="xp" edition="sp2"/>
        <vers num="xp" edition="sp2:home"/>
        <vers num="xp_tablet_pc" edition="sp1"/>
        <vers num="xp_tablet_pc" edition="sp2"/>
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:pro"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:pro"/>
        <vers num="" edition="sp3"/>
        <vers num="" edition="sp3:pro"/>
        <vers num="" edition="sp4"/>
        <vers num="" edition="sp4:server"/>
        <vers num="" edition="sp4:pro"/>
      </prod>
      <prod vendor="microsoft" name="windows_2000_advanced_server">
        <vers num="sp1"/>
        <vers num="sp2"/>
        <vers num="sp3"/>
        <vers num="sp4"/>
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="datacenter_edition"/>
        <vers num="datacenter_edition_64-bit"/>
        <vers num="enterprise_edition"/>
        <vers num="enterprise_edition_64-bit"/>
        <vers num="standard"/>
        <vers num="standard_64-bit"/>
        <vers num="web_edition"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2000">
        <vers num="none"/>
        <vers num="sp1"/>
        <vers num="sp2"/>
        <vers num="sp3"/>
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="datacenter_sp1"/>
        <vers num="enterprise_sp1"/>
        <vers num="standard_sp1"/>
        <vers num="web_edition_sp1"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":x64"/>
        <vers num="" edition=":pro"/>
        <vers num="" edition=":media_center"/>
        <vers num="" edition=":home"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:home"/>
        <vers num="" edition="sp1:pro"/>
        <vers num="" edition="sp1:media_center"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:pro"/>
        <vers num="" edition="sp2:media_center"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0006" published="2006-02-14" name="CVE-2006-0006" modified="2011-10-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the bitmap processing routine in Microsoft Windows Media Player 7.1 on Windows 2000 SP4, Media Player 9 on Windows 2000 SP4 and XP SP1, and Media Player 10 on XP SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted bitmap (.BMP) file that specifies a size of 0 but contains additional data.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-045A.html" source="CERT" adv="1">TA06-045A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/291396" source="CERT-VN" adv="1">VU#291396</ref>
      <ref url="http://www.securityfocus.com/bid/16633" source="BID" patch="1">16633</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-005.mspx" source="MS" patch="1" adv="1">MS06-005</ref>
      <ref url="http://www.eeye.com/html/research/advisories/AD20060214.html" source="MISC" patch="1" adv="1">http://www.eeye.com/html/research/advisories/AD20060214.html</ref>
      <ref url="http://securitytracker.com/id?1015627" source="SECTRACK" patch="1">1015627</ref>
      <ref url="http://secunia.com/advisories/18835" source="SECUNIA" patch="1" adv="1">18835</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24488" source="XF">win-media-player-bmp-bo(24488)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0574" source="VUPEN" adv="1">ADV-2006-0574</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425158/100/0/threaded" source="BUGTRAQ">20060215 Windows Media Player BMP Heap Overflow (MS06-005)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424983/100/0/threaded" source="BUGTRAQ" adv="1">20060214 [EEYEB-20051017] Windows Media Player BMP Heap Overflow</ref>
      <ref url="http://securityreason.com/securityalert/423" source="SREASON">423</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1661" source="OVAL" sig="1">oval:org.mitre.oval:def:1661</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1598" source="OVAL" sig="1">oval:org.mitre.oval:def:1598</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1578" source="OVAL" sig="1">oval:org.mitre.oval:def:1578</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1256" source="OVAL" sig="1">oval:org.mitre.oval:def:1256</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_media_player">
        <vers num="10"/>
        <vers num="7.1"/>
        <vers num="9"/>
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp4"/>
        <vers num="" edition="sp4:"/>
        <vers num="" edition="sp4::fr"/>
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="r2"/>
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold"/>
      </prod>
      <prod vendor="microsoft" name="windows_98se">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_me">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:tablet_pc"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:tablet_pc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0007" published="2006-07-11" name="CVE-2006-0007" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in GIFIMP32.FLT, as used in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via a crafted GIF image that triggers memory corruption when it is parsed.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-192A.html" source="CERT">TA06-192A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/668564" source="CERT-VN">VU#668564</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-039.mspx" source="MS" patch="1">MS06-039</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2757" source="VUPEN">ADV-2006-2757</ref>
      <ref url="http://www.securityfocus.com/bid/18915" source="BID">18915</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/439887/100/0/threaded" source="BUGTRAQ">20060712 NSFOCUS SA2006-04 : Microsoft Office GIF Filter Buffer Overflow Vulnerability</ref>
      <ref url="http://www.osvdb.org/27146" source="OSVDB">27146</ref>
      <ref url="http://securitytracker.com/id?1016470" source="SECTRACK">1016470</ref>
      <ref url="http://secunia.com/advisories/21013" source="SECUNIA">21013</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2006-q3/0005.html" source="VULNWATCH">20060712 NSFOCUS SA2006-04 : Microsoft Office GIF Filter Buffer Overflow Vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:21" source="OVAL" sig="1">oval:org.mitre.oval:def:21</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2000" edition="sp3"/>
        <vers num="2003" edition="sp1"/>
        <vers num="2003" edition="sp2"/>
        <vers num="xp" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0008" published="2006-02-14" name="CVE-2006-0008" modified="2011-03-28" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The ShellAbout API call in Korean Input Method Editor (IME) in Korean versions of Microsoft Windows XP SP1 and SP2, Windows Server 2003 up to SP1, and Office 2003, allows local users to gain privileges by launching the "shell about dialog box" and clicking the "End-User License Agreement" link, which executes Notepad with the privileges of the program that displays the about box.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/739844" source="CERT-VN" adv="1">VU#739844</ref>
      <ref url="http://www.securityfocus.com/bid/16643" source="BID" patch="1">16643</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-009.mspx" source="MS" patch="1" adv="1">MS06-009</ref>
      <ref url="http://securitytracker.com/id?1015631" source="SECTRACK" patch="1">1015631</ref>
      <ref url="http://secunia.com/advisories/18859" source="SECUNIA" patch="1" adv="1">18859</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24492" source="XF">win-korean-ime-privilege-elevation(24492)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0578" source="VUPEN" adv="1">ADV-2006-0578</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425141/100/0/threaded" source="BUGTRAQ">20060215 Security advisory: Windows IME Vulnerability (MS06-009)</ref>
      <ref url="http://www.ryanstyle.com/alert/my/5/ms06_009_eng.html" source="MISC" adv="1">http://www.ryanstyle.com/alert/my/5/ms06_009_eng.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:727" source="OVAL" sig="1">oval:org.mitre.oval:def:727</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1688" source="OVAL" sig="1">oval:org.mitre.oval:def:1688</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1664" source="OVAL" sig="1">oval:org.mitre.oval:def:1664</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1650" source="OVAL" sig="1">oval:org.mitre.oval:def:1650</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1595" source="OVAL" sig="1">oval:org.mitre.oval:def:1595</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2003" edition=""/>
        <vers num="2003" edition=":student_teacher"/>
        <vers num="2003" edition="sp1"/>
        <vers num="2003" edition="sp2"/>
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="datacenter_64-bit" edition="sp1"/>
        <vers num="enterprise" edition=""/>
        <vers num="enterprise" edition=":64-bit"/>
        <vers num="enterprise" edition="sp1"/>
        <vers num="enterprise_64-bit" edition="sp1"/>
        <vers num="r2" edition=""/>
        <vers num="r2" edition=":64-bit"/>
        <vers num="r2" edition=":datacenter_64-bit"/>
        <vers num="r2" edition="sp1"/>
        <vers num="standard" edition=""/>
        <vers num="standard" edition=":64-bit"/>
        <vers num="standard" edition="sp1"/>
        <vers num="standard_64-bit"/>
        <vers num="web" edition="sp1"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":media_center"/>
        <vers num="" edition=":home"/>
        <vers num="" edition=":64-bit"/>
        <vers num="" edition="gold"/>
        <vers num="" edition="gold:professional"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:home"/>
        <vers num="" edition="sp1:media_center"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:home"/>
        <vers num="" edition="sp2:media_center"/>
        <vers num="" edition="sp2:tablet_pc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0009" published="2006-03-14" name="CVE-2006-0009" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft Office 2000 SP3, XP SP3, and other versions and packages, allows user-assisted attackers to execute arbitrary code via a routing slip that is longer than specified by the provided length field, as exploited by malware such as TROJ_MDROPPER.BH and Trojan.PPDropper.E in attacks against PowerPoint.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-073A.html" source="CERT" adv="1">TA06-073A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/682820" source="CERT-VN" adv="1">VU#682820</ref>
      <ref url="http://www.securityfocus.com/bid/17000" source="BID" patch="1">17000</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427671/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20060314 SYMSA-2006-001: Buffer overflow in Microsoft Office 2000, Office XP (2002), and Office 2003 Routing Slip Metadata</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-012.mspx" source="MS" patch="1">MS06-012</ref>
      <ref url="http://securitytracker.com/id?1015766" source="SECTRACK" patch="1">1015766</ref>
      <ref url="http://secunia.com/advisories/19138" source="SECUNIA" patch="1" adv="1">19138</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/29009" source="XF">powerpoint-presentation-code-execution(29009)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25009" source="XF">office-routing-slip-bo(25009)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3678" source="VUPEN">ADV-2006-3678</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0950" source="VUPEN">ADV-2006-0950</ref>
      <ref url="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ%5FMDROPPER%2EBH" source="MISC">http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ%5FMDROPPER%2EBH</ref>
      <ref url="http://www.symantec.com/security_response/writeup.jsp?docid=2006-091810-5028-99" source="MISC">http://www.symantec.com/security_response/writeup.jsp?docid=2006-091810-5028-99</ref>
      <ref url="http://www.symantec.com/enterprise/research/SYMSA-2006-001.txt" source="MISC">http://www.symantec.com/enterprise/research/SYMSA-2006-001.txt</ref>
      <ref url="http://www.securityfocus.com/bid/20059" source="BID">20059</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446425/100/0/threaded" source="BUGTRAQ">20060919 Microsoft PowerPoint 0-day Vulnerability FAQ - September written</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446370/100/0/threaded" source="BUGTRAQ">20060919 New PowerPoint 0-day Trojan in the wild</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/444051/100/200/threaded" source="BUGTRAQ">20060822 Major updates in PowerPoint FAQ document - not a 0-day issue</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/443890/100/0/threaded" source="BUGTRAQ">20060819 New PowerPoint 0-day and Trojan - FAQ document ready</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432004/30/5340/threaded" source="BUGTRAQ">20060422 PowerPoint Phishing Trojan</ref>
      <ref url="http://www.osvdb.org/23903" source="OSVDB">23903</ref>
      <ref url="http://www.darkreading.com/document.asp?doc_id=101970" source="MISC">http://www.darkreading.com/document.asp?doc_id=101970</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm</ref>
      <ref url="http://securitytracker.com/id?1016886" source="SECTRACK">1016886</ref>
      <ref url="http://securitytracker.com/id?1016720" source="SECTRACK">1016720</ref>
      <ref url="http://secunia.com/advisories/19238" source="SECUNIA">19238</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-September/049540.html" source="FULLDISC">20060919 New PowerPoint 0-day Trojan in the wild</ref>
      <ref url="http://isc.sans.org/diary.php?storyid=1618" source="MISC">http://isc.sans.org/diary.php?storyid=1618</ref>
      <ref url="http://blogs.securiteam.com/?p=559" source="MISC">http://blogs.securiteam.com/?p=559</ref>
      <ref url="http://blogs.securiteam.com/?p=557" source="MISC">http://blogs.securiteam.com/?p=557</ref>
      <ref url="http://blogs.securiteam.com/?author=28" source="MISC">http://blogs.securiteam.com/?author=28</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-08/0597.html" source="FULLDISC">20060822 Major updates in PowerPoint FAQ document - not a 0-day issue</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:798" source="OVAL" sig="1">oval:org.mitre.oval:def:798</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1653" source="OVAL" sig="1">oval:org.mitre.oval:def:1653</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1553" source="OVAL" sig="1">oval:org.mitre.oval:def:1553</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1504" source="OVAL" sig="1">oval:org.mitre.oval:def:1504</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2000" edition="sp3"/>
        <vers num="2003" edition="sp1"/>
        <vers num="2003" edition="sp2"/>
        <vers num="2004" edition=""/>
        <vers num="2004" edition=":mac"/>
        <vers num="v.x" edition=""/>
        <vers num="v.x" edition=":mac"/>
        <vers num="xp" edition="sp3"/>
      </prod>
      <prod vendor="microsoft" name="works">
        <vers num="2000"/>
        <vers num="2001"/>
        <vers num="2002"/>
        <vers num="2003"/>
        <vers num="2004"/>
        <vers num="2005"/>
        <vers num="2006"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0010" published="2006-01-10" name="CVE-2006-0010" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in T2EMBED.DLL in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1, Windows 98, and Windows ME allows remote attackers to execute arbitrary code via an e-mail message or web page with a crafted Embedded Open Type (EOT) web font that triggers the overflow during decompression.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-010A.html" source="CERT">TA06-010A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/915930" source="CERT-VN" adv="1">VU#915930</ref>
      <ref url="http://www.securityfocus.com/bid/16194" source="BID" patch="1">16194</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-002.mspx" source="MS" patch="1" adv="1">MS06-002</ref>
      <ref url="http://secunia.com/advisories/18365" source="SECUNIA" patch="1" adv="1">18365</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/23922" source="XF">win-embedded-fonts-bo(23922)</ref>
      <ref url="http://www130.nortelnetworks.com/cgi-bin/eserv/cs/main.jsp?cscat=BLTNDETAIL&amp;DocumentOID=375525" source="MISC">http://www130.nortelnetworks.com/cgi-bin/eserv/cs/main.jsp?cscat=BLTNDETAIL&amp;DocumentOID=375525</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0118" source="VUPEN">ADV-2006-0118</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421885/100/0/threaded" source="BUGTRAQ">20060110 [EEYEB-2000801] - Windows Embedded Open Type (EOT) Font Heap Overflow Vulnerability</ref>
      <ref url="http://www.osvdb.org/18829" source="OSVDB">18829</ref>
      <ref url="http://www.eeye.com/html/Research/Advisories/EEYEB20050801.html" source="EEYE">EEYEB20050801</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-004.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-004.htm</ref>
      <ref url="http://securitytracker.com/id?1015459" source="SECTRACK">1015459</ref>
      <ref url="http://secunia.com/advisories/18391" source="SECUNIA" adv="1">18391</ref>
      <ref url="http://secunia.com/advisories/18311" source="SECUNIA" adv="1">18311</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:714" source="OVAL" sig="1">oval:org.mitre.oval:def:714</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:698" source="OVAL" sig="1">oval:org.mitre.oval:def:698</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1491" source="OVAL" sig="1">oval:org.mitre.oval:def:1491</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1462" source="OVAL" sig="1">oval:org.mitre.oval:def:1462</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1185" source="OVAL" sig="1">oval:org.mitre.oval:def:1185</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1126" source="OVAL" sig="1">oval:org.mitre.oval:def:1126</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":professional"/>
        <vers num="" edition=":server"/>
        <vers num="" edition=":advanced_server"/>
        <vers num="" edition=":datacenter_server"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:datacenter_server"/>
        <vers num="" edition="sp1:advanced_server"/>
        <vers num="" edition="sp1:professional"/>
        <vers num="" edition="sp1:server"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:advanced_server"/>
        <vers num="" edition="sp2:professional"/>
        <vers num="" edition="sp2:datacenter_server"/>
        <vers num="" edition="sp2:server"/>
        <vers num="" edition="sp3"/>
        <vers num="" edition="sp3:server"/>
        <vers num="" edition="sp3:professional"/>
        <vers num="" edition="sp3:datacenter_server"/>
        <vers num="" edition="sp3:advanced_server"/>
        <vers num="" edition="sp4"/>
        <vers num="" edition="sp4:datacenter_server"/>
        <vers num="" edition="sp4:server"/>
        <vers num="" edition="sp4:advanced_server"/>
        <vers num="" edition="sp4:professional"/>
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="datacenter_64-bit" edition="sp1"/>
        <vers num="enterprise" edition=""/>
        <vers num="enterprise" edition=":64-bit"/>
        <vers num="enterprise" edition="sp1"/>
        <vers num="enterprise_64-bit" edition="sp1"/>
        <vers num="r2" edition=""/>
        <vers num="r2" edition=":64-bit"/>
        <vers num="r2" edition=":datacenter_64-bit"/>
        <vers num="r2" edition="sp1"/>
        <vers num="standard" edition=""/>
        <vers num="standard" edition=":64-bit"/>
        <vers num="standard" edition="sp1"/>
        <vers num="standard_64-bit"/>
        <vers num="web" edition="sp1"/>
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold"/>
      </prod>
      <prod vendor="microsoft" name="windows_98se">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_me">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="3.5.1" edition="sp1"/>
        <vers num="3.5.1" edition="sp2"/>
        <vers num="3.5.1" edition="sp3"/>
        <vers num="3.5.1" edition="sp4"/>
        <vers num="3.5.1" edition="sp5"/>
        <vers num="3.5.1" edition="sp5:alpha"/>
        <vers num="4.0" edition=""/>
        <vers num="4.0" edition=":terminal_server"/>
        <vers num="4.0" edition=":terminal_server_alpha"/>
        <vers num="4.0" edition=":server"/>
        <vers num="4.0" edition=":enterprise_server"/>
        <vers num="4.0" edition=":alpha"/>
        <vers num="4.0" edition=":workstation"/>
        <vers num="4.0" edition="sp1"/>
        <vers num="4.0" edition="sp1:server"/>
        <vers num="4.0" edition="sp1:workstation"/>
        <vers num="4.0" edition="sp1:terminal_server"/>
        <vers num="4.0" edition="sp1:enterprise_server"/>
        <vers num="4.0" edition="sp1:alpha"/>
        <vers num="4.0" edition="sp2"/>
        <vers num="4.0" edition="sp2:enterprise_server"/>
        <vers num="4.0" edition="sp2:terminal_server"/>
        <vers num="4.0" edition="sp2:server"/>
        <vers num="4.0" edition="sp2:workstation"/>
        <vers num="4.0" edition="sp2:alpha"/>
        <vers num="4.0" edition="sp3"/>
        <vers num="4.0" edition="sp3:workstation"/>
        <vers num="4.0" edition="sp3:server"/>
        <vers num="4.0" edition="sp3:terminal_server"/>
        <vers num="4.0" edition="sp3:alpha"/>
        <vers num="4.0" edition="sp3:enterprise_server"/>
        <vers num="4.0" edition="sp4"/>
        <vers num="4.0" edition="sp4:workstation"/>
        <vers num="4.0" edition="sp4:alpha"/>
        <vers num="4.0" edition="sp4:server"/>
        <vers num="4.0" edition="sp4:enterprise_server"/>
        <vers num="4.0" edition="sp4:terminal_server"/>
        <vers num="4.0" edition="sp5"/>
        <vers num="4.0" edition="sp5:server"/>
        <vers num="4.0" edition="sp5:workstation"/>
        <vers num="4.0" edition="sp5:alpha"/>
        <vers num="4.0" edition="sp5:enterprise_server"/>
        <vers num="4.0" edition="sp5:terminal_server"/>
        <vers num="4.0" edition="sp6"/>
        <vers num="4.0" edition="sp6:terminal_server"/>
        <vers num="4.0" edition="sp6:server"/>
        <vers num="4.0" edition="sp6:workstation"/>
        <vers num="4.0" edition="sp6:alpha"/>
        <vers num="4.0" edition="sp6:enterprise_server"/>
        <vers num="4.0" edition="sp6a"/>
        <vers num="4.0" edition="sp6a:server"/>
        <vers num="4.0" edition="sp6a:enterprise_server"/>
        <vers num="4.0" edition="sp6a:terminal_server"/>
        <vers num="4.0" edition="sp6a:alpha"/>
        <vers num="4.0" edition="sp6a:workstation"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home"/>
        <vers num="" edition=":64-bit"/>
        <vers num="" edition=":media_center"/>
        <vers num="" edition="gold"/>
        <vers num="" edition="gold:professional"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:home"/>
        <vers num="" edition="sp1:media_center"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:tablet_pc"/>
        <vers num="" edition="sp2:home"/>
        <vers num="" edition="sp2:media_center"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0012" published="2006-04-11" name="CVE-2006-0012" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in Windows Explorer in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via attack vectors involving COM objects and "crafted files and directories," aka the "Windows Shell Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-101A.html" source="CERT">TA06-101A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/641460" source="CERT-VN" adv="1">VU#641460</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-015.mspx" source="MS" patch="1">MS06-015</ref>
      <ref url="http://secunia.com/advisories/19606" source="SECUNIA" patch="1" adv="1">19606</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25554" source="XF">win-explorer-com-code-execution(25554)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1320" source="VUPEN">ADV-2006-1320</ref>
      <ref url="http://www.securityfocus.com/bid/17464" source="BID">17464</ref>
      <ref url="http://www.osvdb.org/24516" source="OSVDB">24516</ref>
      <ref url="http://securitytracker.com/id?1015897" source="SECTRACK">1015897</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1764" source="OVAL" sig="1">oval:org.mitre.oval:def:1764</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1743" source="OVAL" sig="1">oval:org.mitre.oval:def:1743</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1679" source="OVAL" sig="1">oval:org.mitre.oval:def:1679</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1448" source="OVAL" sig="1">oval:org.mitre.oval:def:1448</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1191" source="OVAL" sig="1">oval:org.mitre.oval:def:1191</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":advanced_server"/>
        <vers num="" edition=":professional"/>
        <vers num="" edition=":datacenter_server"/>
        <vers num="" edition=":server"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:datacenter_server"/>
        <vers num="" edition="sp1:professional"/>
        <vers num="" edition="sp1:server"/>
        <vers num="" edition="sp1:advanced_server"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:advanced_server"/>
        <vers num="" edition="sp2:professional"/>
        <vers num="" edition="sp2:datacenter_server"/>
        <vers num="" edition="sp2:server"/>
        <vers num="" edition="sp3"/>
        <vers num="" edition="sp3:datacenter_server"/>
        <vers num="" edition="sp3:server"/>
        <vers num="" edition="sp3:professional"/>
        <vers num="" edition="sp3:advanced_server"/>
        <vers num="" edition="sp4"/>
        <vers num="" edition="sp4:server"/>
        <vers num="" edition="sp4:datacenter_server"/>
        <vers num="" edition="sp4:professional"/>
        <vers num="" edition="sp4:advanced_server"/>
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="datacenter_64-bit" edition="sp1"/>
        <vers num="enterprise" edition=""/>
        <vers num="enterprise" edition=":64-bit"/>
        <vers num="enterprise" edition="sp1"/>
        <vers num="enterprise_64-bit" edition="sp1"/>
        <vers num="r2" edition=""/>
        <vers num="r2" edition=":64-bit"/>
        <vers num="r2" edition=":datacenter_64-bit"/>
        <vers num="r2" edition="sp1"/>
        <vers num="standard" edition=""/>
        <vers num="standard" edition=":64-bit"/>
        <vers num="standard" edition="sp1"/>
        <vers num="standard_64-bit"/>
        <vers num="web" edition="sp1"/>
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold"/>
      </prod>
      <prod vendor="microsoft" name="windows_98se">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_me">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":media_center"/>
        <vers num="" edition=":home"/>
        <vers num="" edition=":64-bit"/>
        <vers num="" edition="gold"/>
        <vers num="" edition="gold:professional"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:home"/>
        <vers num="" edition="sp1:media_center"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:home"/>
        <vers num="" edition="sp2:media_center"/>
        <vers num="" edition="sp2:tablet_pc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0013" published="2006-02-14" name="CVE-2006-0013" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Buffer overflow in the Web Client service (WebClnt.dll) for Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote authenticated users or Guests to execute arbitrary code via crafted RPC requests, a different vulnerability than CVE-2005-1207.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/388900" source="CERT-VN" adv="1">VU#388900</ref>
      <ref url="http://www.securityfocus.com/bid/16636" source="BID" patch="1">16636</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-008.mspx" source="MS" patch="1">MS06-008</ref>
      <ref url="http://securitytracker.com/id?1015630" source="SECTRACK" patch="1">1015630</ref>
      <ref url="http://secunia.com/advisories/18857" source="SECUNIA" patch="1" adv="1">18857</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24491" source="XF">msrpc-webclient-message-bo(24491)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0577" source="VUPEN">ADV-2006-0577</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:716" source="OVAL" sig="1">oval:org.mitre.oval:def:716</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:683" source="OVAL" sig="1">oval:org.mitre.oval:def:683</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1602" source="OVAL" sig="1">oval:org.mitre.oval:def:1602</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1547" source="OVAL" sig="1">oval:org.mitre.oval:def:1547</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1220" source="OVAL" sig="1">oval:org.mitre.oval:def:1220</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="datacenter_64-bit" edition="sp1"/>
        <vers num="enterprise" edition=""/>
        <vers num="enterprise" edition=":64-bit"/>
        <vers num="enterprise" edition="sp1"/>
        <vers num="enterprise_64-bit" edition="sp1"/>
        <vers num="r2" edition=""/>
        <vers num="r2" edition=":64-bit"/>
        <vers num="r2" edition=":datacenter_64-bit"/>
        <vers num="r2" edition="sp1"/>
        <vers num="standard" edition=""/>
        <vers num="standard" edition=":64-bit"/>
        <vers num="standard" edition="sp1"/>
        <vers num="standard_64-bit"/>
        <vers num="web" edition="sp1"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home"/>
        <vers num="" edition=":64-bit"/>
        <vers num="" edition="gold"/>
        <vers num="" edition="gold:professional"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:home"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:home"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0014" published="2006-04-11" name="CVE-2006-0014" modified="2011-03-07" discovered="2005-09-20" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft Outlook Express 5.5 and 6 allows remote attackers to execute arbitrary code via a crafted Windows Address Book (WAB) file containing "certain Unicode strings" and modified length values.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-016.mspx" source="MS" patch="1">MS06-016</ref>
      <ref url="http://secunia.com/advisories/19617" source="SECUNIA" patch="1" adv="1">19617</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-06-007.html" source="MISC" adv="1">http://www.zerodayinitiative.com/advisories/ZDI-06-007.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1321" source="VUPEN">ADV-2006-1321</ref>
      <ref url="http://www.securityfocus.com/bid/17459" source="BID">17459</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430645/100/0/threaded" source="BUGTRAQ" adv="1">20060411 ZDI-06-007: Microsoft Windows Address Book (WAB) File Format Parsing Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25535" source="XF">outlook-express-wab-bo(25535)</ref>
      <ref url="http://securitytracker.com/id?1015898" source="SECTRACK">1015898</ref>
      <ref url="http://securityreason.com/securityalert/691" source="SREASON">691</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-April/045003.html" source="FULLDISC">20060411 ZDI-06-007: Microsoft Windows Address Book (WAB) File Format Parsing Vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:812" source="OVAL" sig="1">oval:org.mitre.oval:def:812</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1791" source="OVAL" sig="1">oval:org.mitre.oval:def:1791</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1780" source="OVAL" sig="1">oval:org.mitre.oval:def:1780</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1771" source="OVAL" sig="1">oval:org.mitre.oval:def:1771</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1769" source="OVAL" sig="1">oval:org.mitre.oval:def:1769</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1682" source="OVAL" sig="1">oval:org.mitre.oval:def:1682</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1611" source="OVAL" sig="1">oval:org.mitre.oval:def:1611</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="outlook_express">
        <vers num="5.5" edition="sp1"/>
        <vers num="5.5" edition="sp2"/>
        <vers num="6.0" edition="sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0015" published="2006-04-11" name="CVE-2006-0015" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in _vti_bin/_vti_adm/fpadmdll.dll in Microsoft FrontPage Server Extensions 2002 and SharePoint Team Services allows remote attackers to inject arbitrary web script or HTML, then leverage the attack to execute arbitrary programs or create new accounts, via the (1) operation, (2) command, and (3) name parameters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17452" source="BID" patch="1">17452</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS06-017.mspx" source="MS" patch="1">MS06-017</ref>
      <ref url="http://www.argeniss.com/research/ARGENISS-ADV-040602.txt" source="MISC" patch="1" adv="1">http://www.argeniss.com/research/ARGENISS-ADV-040602.txt</ref>
      <ref url="http://securitytracker.com/id?1015896" source="SECTRACK" patch="1">1015896</ref>
      <ref url="http://securitytracker.com/id?1015895" source="SECTRACK" patch="1">1015895</ref>
      <ref url="http://secunia.com/advisories/19623" source="SECUNIA" patch="1" adv="1">19623</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1322" source="VUPEN">ADV-2006-1322</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430803/100/0/threaded" source="BUGTRAQ">20060412 Vulnerability in Microsoft FrontPage Server Extensions Could Allow Cross-Site Scripting</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25537" source="XF">fpse-html-xss(25537)</ref>
      <ref url="http://securityreason.com/securityalert/704" source="SREASON">704</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1748" source="OVAL" sig="1">oval:org.mitre.oval:def:1748</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="frontpage_server_extensions">
        <vers num="2002"/>
      </prod>
      <prod vendor="microsoft" name="sharepoint_team_services">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2006-0018" reject="1" published="2005-11-29" name="CVE-2006-0018" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-3899.  Reason: This candidate is a duplicate of CVE-2005-3899.  Notes: All CVE users should reference CVE-2005-3899 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0019" published="2006-01-20" name="CVE-2006-0019" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the encodeURI and decodeURI functions in the kjs JavaScript interpreter engine in KDE 3.2.0 through 3.5.0 allows remote attackers to execute arbitrary code via a crafted, UTF-8 encoded URI.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422464/100/0/threaded" source="BUGTRAQ" patch="1">20060119 [KDE Security Advisory] kjs encodeuri/decodeuri heap overflow</ref>
      <ref url="http://www.kde.org/info/security/advisory-20060119-1.txt" source="CONFIRM" patch="1" adv="1">http://www.kde.org/info/security/advisory-20060119-1.txt</ref>
      <ref url="http://secunia.com/advisories/18500" source="SECUNIA" patch="1" adv="1">18500</ref>
      <ref url="ftp://ftp.kde.org/pub/kde/security_patches/post-3.4.3-kdelibs-kjs.diff" source="CONFIRM" patch="1">ftp://ftp.kde.org/pub/kde/security_patches/post-3.4.3-kdelibs-kjs.diff</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0265" source="VUPEN">ADV-2006-0265</ref>
      <ref url="http://www.ubuntu.com/usn/usn-245-1" source="UBUNTU">USN-245-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422489/100/0/threaded" source="SUSE">SUSE-SA:2006:003</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0184.html" source="REDHAT" adv="1">RHSA-2006:0184</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200601-11.xml" source="GENTOO">GLSA-200601-11</ref>
      <ref url="http://www.debian.org/security/2006/dsa-948" source="DEBIAN" adv="1">DSA-948</ref>
      <ref url="http://secunia.com/advisories/18570" source="SECUNIA">18570</ref>
      <ref url="http://secunia.com/advisories/18561" source="SECUNIA" adv="1">18561</ref>
      <ref url="http://secunia.com/advisories/18559" source="SECUNIA">18559</ref>
      <ref url="http://secunia.com/advisories/18552" source="SECUNIA">18552</ref>
      <ref url="http://secunia.com/advisories/18540" source="SECUNIA" adv="1">18540</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11858" source="OVAL">oval:org.mitre.oval:def:11858</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24242" source="XF">kde-kjs-bo(24242)</ref>
      <ref url="http://www.securityfocus.com/bid/16325" source="BID">16325</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427976/100/0/threaded" source="FEDORA">FLSA:178606</ref>
      <ref url="http://www.osvdb.org/22659" source="OSVDB">22659</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:019" source="MANDRIVA">MDKSA-2006:019</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.361107" source="SLACKWARE">SSA:2006-045-05</ref>
      <ref url="http://securitytracker.com/id?1015512" source="SECTRACK">1015512</ref>
      <ref url="http://securityreason.com/securityalert/364" source="SREASON">364</ref>
      <ref url="http://secunia.com/advisories/18899" source="SECUNIA">18899</ref>
      <ref url="http://secunia.com/advisories/18583" source="SECUNIA">18583</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kde" name="kde">
        <vers num="3.2"/>
        <vers num="3.2.0"/>
        <vers num="3.2.0_beta1"/>
        <vers num="3.2.1"/>
        <vers num="3.2.2"/>
        <vers num="3.2.3"/>
        <vers num="3.2.x"/>
        <vers num="3.3"/>
        <vers num="3.3.0"/>
        <vers num="3.3.1"/>
        <vers num="3.3.2"/>
        <vers num="3.3.x"/>
        <vers num="3.4"/>
        <vers num="3.4.0"/>
        <vers num="3.4.1"/>
        <vers num="3.4.2"/>
        <vers num="3.5.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0020" published="2006-01-10" name="CVE-2006-0020" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">An unspecified Microsoft WMF parsing application, as used in Internet Explorer 5.01 SP4 on Windows 2000 SP4, and 5.5 SP2 on Windows Millennium, and possibly other versions, allows attackers to cause a denial of service (crash) and possibly execute code via a crafted WMF file with a manipulated WMF header size, possibly involving an integer overflow, a different vulnerability than CVE-2005-4560, and aka "WMF Image Parsing Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/312956" source="CERT-VN" patch="1" adv="1">VU#312956</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-045A.html" source="CERT" adv="1">TA06-045A</ref>
      <ref url="http://www.securityfocus.com/bid/16516" source="BID" patch="1">16516</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-004.mspx" source="MS" patch="1">MS06-004</ref>
      <ref url="http://secunia.com/advisories/18729" source="SECUNIA" patch="1" adv="1">18729</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0469" source="VUPEN">ADV-2006-0469</ref>
      <ref url="http://www.osvdb.org/22976" source="OSVDB">22976</ref>
      <ref url="http://www.microsoft.com/technet/security/advisory/913333.mspx" source="CONFIRM" adv="1">http://www.microsoft.com/technet/security/advisory/913333.mspx</ref>
      <ref url="http://secunia.com/advisories/18912" source="SECUNIA" adv="1">18912</ref>
      <ref url="http://linuxbox.org/pipermail/funsec/2006-January/002828.html" source="MLIST" adv="1">[funsec] 20060110 Another WMF flaw without a Microsoft patch</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1638" source="OVAL" sig="1">oval:org.mitre.oval:def:1638</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4"/>
        <vers num="" edition="sp4:"/>
        <vers num="" edition="sp4::fr"/>
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="r2"/>
        <vers num="sp1"/>
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold"/>
      </prod>
      <prod vendor="microsoft" name="windows_98se">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_me">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:tablet_pc"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:tablet_pc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0021" published="2006-02-14" name="CVE-2006-0021" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote attackers to cause a denial of service (hang) via an IGMP packet with an invalid IP option, aka the "IGMP v3 DoS Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-045A.html" source="CERT" adv="1">TA06-045A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/839284" source="CERT-VN" adv="1">VU#839284</ref>
      <ref url="http://www.securityfocus.com/bid/16645" source="BID" patch="1">16645</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-007.mspx" source="MS" patch="1" adv="1">MS06-007</ref>
      <ref url="http://secunia.com/advisories/18853" source="SECUNIA" patch="1" adv="1">18853</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24489" source="XF">win-igmpv3-dos(24489)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0576" source="VUPEN" adv="1">ADV-2006-0576</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/482658/30/4350/threaded" source="BUGTRAQ">20071023 SYMSA-2007-012: Microsoft Windows CE IGMP Denial of Service</ref>
      <ref url="http://www.securiteam.com/exploits/5PP0T0KI0O.html" source="MISC">http://www.securiteam.com/exploits/5PP0T0KI0O.html</ref>
      <ref url="http://www.milw0rm.com/exploits/1599" source="MILW0RM">1599</ref>
      <ref url="http://securitytracker.com/id?1015629" source="SECTRACK">1015629</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:678" source="OVAL" sig="1">oval:org.mitre.oval:def:678</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1662" source="OVAL" sig="1">oval:org.mitre.oval:def:1662</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1647" source="OVAL" sig="1">oval:org.mitre.oval:def:1647</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1425" source="OVAL" sig="1">oval:org.mitre.oval:def:1425</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1310" source="OVAL" sig="1">oval:org.mitre.oval:def:1310</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="datacenter_64-bit" edition="sp1"/>
        <vers num="enterprise" edition=""/>
        <vers num="enterprise" edition=":64-bit"/>
        <vers num="enterprise" edition="sp1"/>
        <vers num="enterprise_64-bit"/>
        <vers num="r2" edition=""/>
        <vers num="r2" edition=":64-bit"/>
        <vers num="r2" edition=":datacenter_64-bit"/>
        <vers num="r2" edition="sp1"/>
        <vers num="standard" edition=""/>
        <vers num="standard" edition=":64-bit"/>
        <vers num="standard" edition="sp1"/>
        <vers num="standard_64-bit"/>
        <vers num="web" edition="sp1"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":media_center"/>
        <vers num="" edition=":home"/>
        <vers num="" edition=":64-bit"/>
        <vers num="" edition=":embedded"/>
        <vers num="" edition="gold"/>
        <vers num="" edition="gold:professional"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:embedded"/>
        <vers num="" edition="sp1:64-bit"/>
        <vers num="" edition="sp1:home"/>
        <vers num="" edition="sp1:media_center"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:home"/>
        <vers num="" edition="sp2:media_center"/>
        <vers num="" edition="sp2:tablet_pc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0022" published="2006-06-13" name="CVE-2006-0022" modified="2011-04-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Unspecified vulnerability in Microsoft PowerPoint in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP1 and SP2, Office 2004 for Mac, and v. X for Mac allows user-assisted attackers to execute arbitrary code via a PowerPoint document with a malformed record, which triggers memory corruption.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-164A.html" source="CERT">TA06-164A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/190089" source="CERT-VN">VU#190089</ref>
      <ref url="http://www.securityfocus.com/bid/18382" source="BID" patch="1">18382</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-028.mspx" source="MS" patch="1" adv="1">MS06-028</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26784" source="XF">powerpoint-record-bo(26784)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2325" source="VUPEN" adv="1">ADV-2006-2325</ref>
      <ref url="http://www.osvdb.org/26435" source="OSVDB">26435</ref>
      <ref url="http://securitytracker.com/id?1016287" source="SECTRACK">1016287</ref>
      <ref url="http://secunia.com/advisories/20633" source="SECUNIA" adv="1">20633</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1984" source="OVAL" sig="1">oval:org.mitre.oval:def:1984</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1836" source="OVAL" sig="1">oval:org.mitre.oval:def:1836</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1069" source="OVAL" sig="1">oval:org.mitre.oval:def:1069</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="powerpoint">
        <vers num="2000" edition="sp2"/>
        <vers num="2000" edition="sp3"/>
        <vers num="2000" edition="sr1"/>
        <vers num="2002" edition="sp1"/>
        <vers num="2002" edition="sp2"/>
        <vers num="2002" edition="sp3"/>
        <vers num="2003" edition="sp1"/>
        <vers num="2003" edition="sp2"/>
        <vers num="2003" edition="sp3"/>
        <vers num="2004" edition=""/>
        <vers num="2004" edition=":mac"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0023" published="2006-02-07" name="CVE-2006-0023" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="4.3" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.1" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Microsoft Windows XP SP1 and SP2 before August 2004, and possibly other operating systems and versions, uses insecure default ACLs that allow the Authenticated Users group to gain privileges by modifying critical configuration information for the (1) Simple Service Discovery Protocol (SSDP), (2) Universal Plug and Play Device Host (UPnP), (3) NetBT, (4) SCardSvr, (5) DHCP, and (6) DnsCache services, aka "Permissive Windows Services DACLs."  NOTE: the NetBT, SCardSvr, DHCP, DnsCache already require privileged access to exploit.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <config/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/953860" source="CERT-VN" adv="1">VU#953860</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-011.mspx" source="MS" patch="1">MS06-011</ref>
      <ref url="http://secunia.com/advisories/18756" source="SECUNIA" patch="1" adv="1">18756</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24463" source="XF">win-auth-users-insecure-permissions(24463)</ref>
      <ref url="http://www130.nortelnetworks.com/cgi-bin/eserv/cs/main.jsp?cscat=BLTNDETAIL&amp;DocumentOID=391523&amp;RenditionID=" source="CONFIRM">http://www130.nortelnetworks.com/cgi-bin/eserv/cs/main.jsp?cscat=BLTNDETAIL&amp;DocumentOID=391523&amp;RenditionID=</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0417" source="VUPEN" adv="1">ADV-2006-0417</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423587/100/0/threaded" source="BUGTRAQ">20060131 Windows Access Control Demystified</ref>
      <ref url="http://www.microsoft.com/technet/security/advisory/914457.mspx" source="MISC" adv="1">http://www.microsoft.com/technet/security/advisory/914457.mspx</ref>
      <ref url="http://www.cs.princeton.edu/~sudhakar/papers/winval.pdf" source="MISC">http://www.cs.princeton.edu/~sudhakar/papers/winval.pdf</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm</ref>
      <ref url="http://securitytracker.com/id?1015765" source="SECTRACK">1015765</ref>
      <ref url="http://securitytracker.com/id?1015595" source="SECTRACK">1015595</ref>
      <ref url="http://secunia.com/advisories/19313" source="SECUNIA" adv="1">19313</ref>
      <ref url="http://secunia.com/advisories/19238" source="SECUNIA" adv="1">19238</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1696" source="OVAL" sig="1">oval:org.mitre.oval:def:1696</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1671" source="OVAL" sig="1">oval:org.mitre.oval:def:1671</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:tablet_pc"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:tablet_pc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0024" published="2006-03-15" name="CVE-2006-0024" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Adobe Flash Player 8.0.22.0 and earlier allow remote attackers to execute arbitrary code via a crafted SWF file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-352A.html" source="CERT">TA07-352A</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-132A.html" source="CERT">TA06-132A</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-129A.html" source="CERT">TA06-129A</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-075A.html" source="CERT">TA06-075A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/945060" source="CERT-VN">VU#945060</ref>
      <ref url="http://www.macromedia.com/devnet/security/security_zone/apsb06-03.html" source="CONFIRM" patch="1" adv="1">http://www.macromedia.com/devnet/security/security_zone/apsb06-03.html</ref>
      <ref url="http://secunia.com/advisories/19218" source="SECUNIA" patch="1" adv="1">19218</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25005" source="XF">macromedia-swf-code-execution(25005)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/4238" source="VUPEN">ADV-2007-4238</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1779" source="VUPEN">ADV-2006-1779</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1744" source="VUPEN">ADV-2006-1744</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1262" source="VUPEN">ADV-2006-1262</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0952" source="VUPEN">ADV-2006-0952</ref>
      <ref url="http://www.securityfocus.com/bid/17106" source="BID">17106</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0268.html" source="REDHAT" adv="1">RHSA-2006:0268</ref>
      <ref url="http://www.osvdb.org/23908" source="OSVDB">23908</ref>
      <ref url="http://www.securityfocus.com/bid/17951" source="BID">17951</ref>
      <ref url="http://www.opera.com/docs/changelogs/windows/854/" source="CONFIRM">http://www.opera.com/docs/changelogs/windows/854/</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_15_flashplayer.html" source="SUSE">SUSE-SA:2006:015</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-020.mspx" source="MS">MS06-020</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200603-20.xml" source="GENTOO">GLSA-200603-20</ref>
      <ref url="http://securitytracker.com/id?1015770" source="SECTRACK">1015770</ref>
      <ref url="http://secunia.com/advisories/28136" source="SECUNIA">28136</ref>
      <ref url="http://secunia.com/advisories/20077" source="SECUNIA">20077</ref>
      <ref url="http://secunia.com/advisories/20045" source="SECUNIA">20045</ref>
      <ref url="http://secunia.com/advisories/19328" source="SECUNIA">19328</ref>
      <ref url="http://secunia.com/advisories/19259" source="SECUNIA">19259</ref>
      <ref url="http://secunia.com/advisories/19198" source="SECUNIA">19198</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2007/Dec/msg00002.html" source="APPLE">APPLE-SA-2007-12-17</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/May/msg00003.html" source="APPLE">APPLE-SA-2006-05-11</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=307179" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=307179</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1922" source="OVAL" sig="1">oval:org.mitre.oval:def:1922</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1894" source="OVAL" sig="1">oval:org.mitre.oval:def:1894</ref>
    </refs>
    <vuln_soft>
      <prod vendor="macromedia" name="flash_player">
        <vers num="4.0_r12"/>
        <vers num="5.0"/>
        <vers num="5.0_r50"/>
        <vers num="6.0"/>
        <vers num="6.0.29.0"/>
        <vers num="6.0.40.0"/>
        <vers num="6.0.47.0"/>
        <vers num="6.0.65.0"/>
        <vers num="6.0.79.0"/>
        <vers num="7.0.19.0"/>
        <vers num="7.0.60.0"/>
        <vers num="7.0.61.0"/>
        <vers num="7.0_r19"/>
        <vers prev="1" num="8.0.22.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0025" published="2006-06-13" name="CVE-2006-0025" modified="2011-03-07" discovered="2006-02-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Microsoft Windows Media Player 9 and 10 allows remote attackers to execute arbitrary code via a PNG image with a large chunk size.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-164A.html" source="CERT">TA06-164A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/608020" source="CERT-VN">VU#608020</ref>
      <ref url="http://www.securityfocus.com/bid/18385" source="BID" patch="1">18385</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-024.mspx" source="MS" patch="1" adv="1">MS06-024</ref>
      <ref url="http://www.idefense.com/intelligence/vulnerabilities/display.php?id=406" source="IDEFENSE" patch="1" adv="1">20060613 Windows Media Player PNG Chunk Decoding Stack-Based Buffer Overflow</ref>
      <ref url="http://secunia.com/advisories/20626" source="SECUNIA" patch="1" adv="1">20626</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26788" source="XF">win-media-player-png-bo(26788)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2322" source="VUPEN">ADV-2006-2322</ref>
      <ref url="http://www.osvdb.org/26430" source="OSVDB">26430</ref>
      <ref url="http://securitytracker.com/id?1016284" source="SECTRACK">1016284</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1974" source="OVAL" sig="1">oval:org.mitre.oval:def:1974</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1820" source="OVAL" sig="1">oval:org.mitre.oval:def:1820</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1807" source="OVAL" sig="1">oval:org.mitre.oval:def:1807</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1805" source="OVAL" sig="1">oval:org.mitre.oval:def:1805</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1729" source="OVAL" sig="1">oval:org.mitre.oval:def:1729</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1230" source="OVAL" sig="1">oval:org.mitre.oval:def:1230</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_media_player">
        <vers num="10"/>
        <vers num="9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0026" published="2006-07-11" name="CVE-2006-0026" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows local and possibly remote attackers to execute arbitrary code via crafted Active Server Pages (ASP).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/395588" source="CERT-VN" patch="1">VU#395588</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-192A.html" source="CERT">TA06-192A</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26796" source="XF" patch="1">iis-asp-bo(26796)</ref>
      <ref url="http://www.securityfocus.com/bid/18858" source="BID" patch="1">18858</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-034.mspx" source="MS" patch="1" adv="1">MS06-034</ref>
      <ref url="http://securitytracker.com/id?1016466" source="SECTRACK" patch="1">1016466</ref>
      <ref url="http://secunia.com/advisories/21006" source="SECUNIA" patch="1" adv="1">21006</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2752" source="VUPEN">ADV-2006-2752</ref>
      <ref url="http://www.osvdb.org/27152" source="OSVDB">27152</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2006-07/0316.html" source="BUGTRAQ">20060718 ASP.DLL Include File Buffer Overflow</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:435" source="OVAL" sig="1">oval:org.mitre.oval:def:435</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_information_server">
        <vers num="5.0"/>
        <vers num="5.1"/>
        <vers num="6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0027" published="2006-05-09" name="CVE-2006-0027" modified="2011-04-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in Microsoft Exchange allows remote attackers to execute arbitrary code via e-mail messages with crafted (1) vCal or (2) iCal Calendar properties.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-129A.html" source="CERT" patch="1">TA06-129A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/303452" source="CERT-VN" patch="1">VU#303452</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-019.mspx" source="MS" patch="1">MS06-019</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25556" source="XF">exchange-calendar-code-execution(25556)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1743" source="VUPEN" adv="1">ADV-2006-1743</ref>
      <ref url="http://www.securityfocus.com/bid/17908" source="BID">17908</ref>
      <ref url="http://www.osvdb.org/25338" source="OSVDB">25338</ref>
      <ref url="http://securitytracker.com/id?1016048" source="SECTRACK">1016048</ref>
      <ref url="http://secunia.com/advisories/20029" source="SECUNIA" adv="1">20029</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2035" source="OVAL" sig="1">oval:org.mitre.oval:def:2035</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1996" source="OVAL" sig="1">oval:org.mitre.oval:def:1996</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1818" source="OVAL" sig="1">oval:org.mitre.oval:def:1818</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="exchange_server">
        <vers num="2000" edition="sp3"/>
        <vers num="2003" edition="sp1"/>
        <vers num="2003" edition="sp2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0028" published="2006-03-14" name="CVE-2006-0028" modified="2011-04-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via a BIFF parsing format file containing malformed BOOLERR records that lead to memory corruption, probably involving invalid pointers.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-073A.html" source="CERT" adv="1">TA06-073A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/339878" source="CERT-VN" adv="1">VU#339878</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-012.mspx" source="MS" patch="1">MS06-012</ref>
      <ref url="http://securitytracker.com/id?1015766" source="SECTRACK" patch="1">1015766</ref>
      <ref url="http://secunia.com/advisories/19138" source="SECUNIA" patch="1" adv="1">19138</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25225" source="XF">excel-parsing-format-file-bo(25225)</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-06-004.html" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-06-004.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0950" source="VUPEN" adv="1">ADV-2006-0950</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427632/100/0/threaded" source="BUGTRAQ" adv="1">20060314 ZDI-06-004: Microsoft Excel File Format Parsing Vulnerability</ref>
      <ref url="http://www.osvdb.org/23899" source="OSVDB">23899</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm</ref>
      <ref url="http://securityreason.com/securityalert/583" source="SREASON">583</ref>
      <ref url="http://secunia.com/advisories/19238" source="SECUNIA" adv="1">19238</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1635" source="OVAL" sig="1">oval:org.mitre.oval:def:1635</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1509" source="OVAL" sig="1">oval:org.mitre.oval:def:1509</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1411" source="OVAL" sig="1">oval:org.mitre.oval:def:1411</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1158" source="OVAL" sig="1">oval:org.mitre.oval:def:1158</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2000"/>
        <vers num="2002"/>
        <vers num="2003"/>
        <vers num="2004" edition=""/>
        <vers num="2004" edition=":mac_os_x"/>
        <vers num="x" edition=""/>
        <vers num="x" edition=":mac_os_x"/>
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2000" edition="sp3"/>
        <vers num="2003" edition="sp1"/>
        <vers num="2003" edition="sp2"/>
        <vers num="2004" edition=""/>
        <vers num="2004" edition=":mac"/>
        <vers num="v.x" edition=""/>
        <vers num="v.x" edition=":mac"/>
        <vers num="xp" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0029" published="2006-03-14" name="CVE-2006-0029" modified="2011-04-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed description, which leads to memory corruption.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-073A.html" source="CERT" adv="1">TA06-073A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/235774" source="CERT-VN" adv="1">VU#235774</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-012.mspx" source="MS" patch="1">MS06-012</ref>
      <ref url="http://securitytracker.com/id?1015766" source="SECTRACK" patch="1">1015766</ref>
      <ref url="http://secunia.com/advisories/19138" source="SECUNIA" patch="1" adv="1">19138</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25227" source="XF">excel-description-bo(25227)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0950" source="VUPEN" adv="1">ADV-2006-0950</ref>
      <ref url="http://www.osvdb.org/23900" source="OSVDB">23900</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm</ref>
      <ref url="http://securityreason.com/securityalert/586" source="SREASON">586</ref>
      <ref url="http://securityreason.com/securityalert/585" source="SREASON">585</ref>
      <ref url="http://secunia.com/advisories/19238" source="SECUNIA" adv="1">19238</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1633" source="OVAL" sig="1">oval:org.mitre.oval:def:1633</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1579" source="OVAL" sig="1">oval:org.mitre.oval:def:1579</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1570" source="OVAL" sig="1">oval:org.mitre.oval:def:1570</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1522" source="OVAL" sig="1">oval:org.mitre.oval:def:1522</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2000"/>
        <vers num="2002"/>
        <vers num="2003"/>
        <vers num="2004" edition=""/>
        <vers num="2004" edition=":mac_os_x"/>
        <vers num="x" edition=""/>
        <vers num="x" edition=":mac_os_x"/>
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2000" edition="sp3"/>
        <vers num="2003" edition="sp1"/>
        <vers num="2003" edition="sp2"/>
        <vers num="2004" edition=""/>
        <vers num="2004" edition=":mac"/>
        <vers num="v.x" edition=""/>
        <vers num="v.x" edition=":mac"/>
        <vers num="xp" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0030" published="2006-03-14" name="CVE-2006-0030" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed graphic, which leads to memory corruption.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-073A.html" source="CERT" adv="1">TA06-073A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/123222" source="CERT-VN" adv="1">VU#123222</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-012.mspx" source="MS" patch="1">MS06-012</ref>
      <ref url="http://securitytracker.com/id?1015766" source="SECTRACK" patch="1">1015766</ref>
      <ref url="http://secunia.com/advisories/19138" source="SECUNIA" patch="1" adv="1">19138</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25229" source="XF">excel-graphic-bo(25229)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0950" source="VUPEN" adv="1">ADV-2006-0950</ref>
      <ref url="http://www.securityfocus.com/bid/16181" source="BID">16181</ref>
      <ref url="http://www.osvdb.org/23901" source="OSVDB">23901</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm</ref>
      <ref url="http://secunia.com/advisories/19238" source="SECUNIA" adv="1">19238</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1666" source="OVAL" sig="1">oval:org.mitre.oval:def:1666</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1630" source="OVAL" sig="1">oval:org.mitre.oval:def:1630</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1510" source="OVAL" sig="1">oval:org.mitre.oval:def:1510</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1401" source="OVAL" sig="1">oval:org.mitre.oval:def:1401</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2000"/>
        <vers num="2002"/>
        <vers num="2003"/>
        <vers num="2004" edition=""/>
        <vers num="2004" edition=":mac_os_x"/>
        <vers num="x" edition=""/>
        <vers num="x" edition=":mac_os_x"/>
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2000" edition="sp3"/>
        <vers num="2003" edition="sp1"/>
        <vers num="2003" edition="sp2"/>
        <vers num="2004" edition=""/>
        <vers num="2004" edition=":mac"/>
        <vers num="v.x" edition=""/>
        <vers num="v.x" edition=":mac"/>
        <vers num="xp" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0031" published="2006-03-14" name="CVE-2006-0031" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed record with a modified length value, which leads to memory corruption.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-073A.html" source="CERT" adv="1">TA06-073A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/104302" source="CERT-VN" adv="1">VU#104302</ref>
      <ref url="http://www.securityfocus.com/bid/17101" source="BID" patch="1">17101</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-012.mspx" source="MS" patch="1">MS06-012</ref>
      <ref url="http://securitytracker.com/id?1015766" source="SECTRACK" patch="1">1015766</ref>
      <ref url="http://secunia.com/advisories/19138" source="SECUNIA" patch="1" adv="1">19138</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25228" source="XF">excel-record-bo(25228)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0950" source="VUPEN" adv="1">ADV-2006-0950</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427699/100/0/threaded" source="BUGTRAQ">20060315 [xfocus-SD-060314]Microsoft Office Excel Buffer Overflow Vulnerability</ref>
      <ref url="http://www.osvdb.org/23902" source="OSVDB">23902</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm</ref>
      <ref url="http://securityreason.com/securityalert/589" source="SREASON">589</ref>
      <ref url="http://secunia.com/advisories/19238" source="SECUNIA" adv="1">19238</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-02/1521.html" source="FULLDISC">20060314 [xfocus-SD-060314]Microsoft Office Excel Buffer Overflow Vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:763" source="OVAL" sig="1">oval:org.mitre.oval:def:763</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1750" source="OVAL" sig="1">oval:org.mitre.oval:def:1750</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1525" source="OVAL" sig="1">oval:org.mitre.oval:def:1525</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1327" source="OVAL" sig="1">oval:org.mitre.oval:def:1327</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2000" edition="sp3"/>
        <vers num="2003" edition="sp1"/>
        <vers num="2003" edition="sp2"/>
        <vers num="2004" edition=""/>
        <vers num="2004" edition=":mac"/>
        <vers num="v.x" edition=""/>
        <vers num="v.x" edition=":mac"/>
        <vers num="xp" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0032" published="2006-09-12" name="CVE-2006-0032" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Indexing Service in Microsoft Windows 2000, XP, and Server 2003, when the Encoding option is set to Auto Select, allows remote attackers to inject arbitrary web script or HTML via a UTF-7 encoded URL, which is injected into an error message whose charset is set to UTF-7.</descript>
    </desc>
    <sols>
      <sol source="nvd">Successful exploitation requires that the Indexing service is accessible through IIS.</sol>
    </sols>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-255A.html" source="CERT">TA06-255A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/108884" source="CERT-VN">VU#108884</ref>
      <ref url="http://www.securityfocus.com/bid/19927" source="BID" patch="1">19927</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS06-053.mspx" source="MS" patch="1">MS06-053</ref>
      <ref url="http://secunia.com/advisories/21861" source="SECUNIA" patch="1" adv="1">21861</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/28651" source="XF">ms-indexing-service-xss(28651)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3564" source="VUPEN">ADV-2006-3564</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/447511/100/0/threaded" source="BUGTRAQ">20061001 Microsoft Internet Information Services UTF-7 XSS Vulnerability [MS06-053]</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/447509/100/0/threaded" source="BUGTRAQ">20061002 IE UXSS (Universal XSS in IE, was Re: Microsoft Internet Information Services UTF-7 XSS Vulnerability [MS06-053])</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446630/100/100/threaded" source="HP">SSRT061187</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446630/100/100/threaded" source="HP">HPSBST02134</ref>
      <ref url="http://www.geocities.jp/ptrs_sec/advisory09e.html" source="MISC">http://www.geocities.jp/ptrs_sec/advisory09e.html</ref>
      <ref url="http://securitytracker.com/id?1016826" source="SECTRACK">1016826</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:535" source="OVAL" sig="1">oval:org.mitre.oval:def:535</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":professional"/>
        <vers num="" edition=":server"/>
        <vers num="" edition=":advanced_server"/>
        <vers num="" edition=":datacenter_server"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:datacenter_server"/>
        <vers num="" edition="sp1:professional"/>
        <vers num="" edition="sp1:server"/>
        <vers num="" edition="sp1:advanced_server"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:advanced_server"/>
        <vers num="" edition="sp2:professional"/>
        <vers num="" edition="sp2:datacenter_server"/>
        <vers num="" edition="sp2:server"/>
        <vers num="" edition="sp3"/>
        <vers num="" edition="sp3:datacenter_server"/>
        <vers num="" edition="sp3:server"/>
        <vers num="" edition="sp3:professional"/>
        <vers num="" edition="sp3:advanced_server"/>
        <vers num="" edition="sp4"/>
        <vers num="" edition="sp4:datacenter_server"/>
        <vers num="" edition="sp4:server"/>
        <vers num="" edition="sp4:professional"/>
        <vers num="" edition="sp4:advanced_server"/>
        <vers num="resource_kit"/>
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="datacenter_edition" edition="sp1"/>
        <vers num="datacenter_edition" edition="sp1_beta_1"/>
        <vers num="datacenter_edition_itanium" edition="sp1"/>
        <vers num="datacenter_edition_itanium" edition="sp1_beta_1"/>
        <vers num="enterprise_64-bit"/>
        <vers num="enterprise_edition" edition="sp1"/>
        <vers num="enterprise_edition" edition="sp1_beta_1"/>
        <vers num="enterprise_edition_itanium" edition="sp1"/>
        <vers num="enterprise_edition_itanium" edition="sp1_beta_1"/>
        <vers num="r2" edition=""/>
        <vers num="r2" edition=":datacenter_64-bit"/>
        <vers num="sp1" edition=""/>
        <vers num="sp1" edition=":enterprise"/>
        <vers num="standard" edition="sp1"/>
        <vers num="standard" edition="sp1_beta_1"/>
        <vers num="standard_64-bit"/>
        <vers num="web" edition="sp1"/>
        <vers num="web" edition="sp1_beta_1"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home"/>
        <vers num="" edition=":64-bit"/>
        <vers num="" edition=":media_center"/>
        <vers num="" edition="gold"/>
        <vers num="" edition="gold:professional"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:home"/>
        <vers num="" edition="sp1:media_center"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:home"/>
        <vers num="" edition="sp2:tablet_pc"/>
        <vers num="" edition="sp2:media_center"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0033" published="2006-07-11" name="CVE-2006-0033" modified="2011-04-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via a crafted PNG image that triggers memory corruption when it is parsed.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-192A.html" source="CERT">TA06-192A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/459388" source="CERT-VN">VU#459388</ref>
      <ref url="http://www.securityfocus.com/bid/18913" source="BID" patch="1">18913</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-039.mspx" source="MS" patch="1">MS06-039</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2757" source="VUPEN" adv="1">ADV-2006-2757</ref>
      <ref url="http://www.osvdb.org/27147" source="OSVDB">27147</ref>
      <ref url="http://www.fortinet.com/FortiGuardCenter/advisory/FG-2006-22.html" source="MISC">http://www.fortinet.com/FortiGuardCenter/advisory/FG-2006-22.html</ref>
      <ref url="http://securitytracker.com/id?1016470" source="SECTRACK">1016470</ref>
      <ref url="http://secunia.com/advisories/21013" source="SECUNIA" adv="1">21013</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:163" source="OVAL" sig="1">oval:org.mitre.oval:def:163</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2000" edition="sp3"/>
        <vers num="2003" edition="sp1"/>
        <vers num="2003" edition="sp2"/>
        <vers num="xp" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0034" published="2006-05-09" name="CVE-2006-0034" modified="2011-10-17" discovered="2005-10-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the CRpcIoManagerServer::BuildContext function in msdtcprx.dll for Microsoft Distributed Transaction Coordinator (MSDTC) for Windows NT 4.0 and Windows 2000 SP2 and SP3 allows remote attackers to execute arbitrary code via a long fifth argument to the BuildContextW or BuildContext opcode, which triggers a bug in the NdrAllocate function, aka the MSDTC Invalid Memory Access Vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17906" source="BID" patch="1">17906</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/433430/100/0/threaded" source="BUGTRAQ" patch="1">20060509 [EEYEB20051011A] - Microsoft Distributed Transaction Coordinator Heap Overflow</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms06-018.mspx" source="MS" patch="1">MS06-018</ref>
      <ref url="http://www.eeye.com/html/research/advisories/AD20060509a.html" source="MISC" patch="1" adv="1">http://www.eeye.com/html/research/advisories/AD20060509a.html</ref>
      <ref url="http://secunia.com/advisories/20000" source="SECUNIA" patch="1" adv="1">20000</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25559" source="XF">msdtc-network-message-dos(25559)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1742" source="VUPEN" adv="1">ADV-2006-1742</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/433677/100/0/threaded" source="BUGTRAQ">20060511 Microsoft MSDTC NdrAllocate Validation Vulnerability</ref>
      <ref url="http://www.osvdb.org/25335" source="OSVDB">25335</ref>
      <ref url="http://securitytracker.com/id?1016047" source="SECTRACK">1016047</ref>
      <ref url="http://securityreason.com/securityalert/863" source="SREASON">863</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-05/0269.html" source="FULLDISC">20060510 Microsoft MSDTC NdrAllocate Validation Vulnerability</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-05/0238.html" source="FULLDISC">20060509 [EEYEB20051011A] - Microsoft Distributed Transaction Coordinator Heap Overflow</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1908" source="OVAL" sig="1">oval:org.mitre.oval:def:1908</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1477" source="OVAL" sig="1">oval:org.mitre.oval:def:1477</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1222" source="OVAL" sig="1">oval:org.mitre.oval:def:1222</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="distributed_transaction_coordinator">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":professional"/>
        <vers num="" edition=":server"/>
        <vers num="" edition=":advanced_server"/>
        <vers num="" edition=":datacenter_server"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:datacenter_server"/>
        <vers num="" edition="sp1:professional"/>
        <vers num="" edition="sp1:server"/>
        <vers num="" edition="sp1:advanced_server"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:advanced_server"/>
        <vers num="" edition="sp2:professional"/>
        <vers num="" edition="sp2:datacenter_server"/>
        <vers num="" edition="sp2:server"/>
        <vers num="" edition="sp3"/>
        <vers num="" edition="sp3:datacenter_server"/>
        <vers num="" edition="sp3:server"/>
        <vers num="" edition="sp3:professional"/>
        <vers num="" edition="sp3:advanced_server"/>
        <vers num="" edition="sp4"/>
        <vers num="" edition="sp4:datacenter_server"/>
        <vers num="" edition="sp4:server"/>
        <vers num="" edition="sp4:professional"/>
        <vers num="" edition="sp4:advanced_server"/>
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="enterprise" edition=""/>
        <vers num="enterprise" edition=":64-bit"/>
        <vers num="enterprise_64-bit"/>
        <vers num="r2" edition=""/>
        <vers num="r2" edition=":datacenter_64-bit"/>
        <vers num="r2" edition=":64-bit"/>
        <vers num="standard" edition=""/>
        <vers num="standard" edition=":64-bit"/>
        <vers num="web"/>
      </prod>
      <prod vendor="microsoft" name="windows_nt">
        <vers num="4.0" edition=""/>
        <vers num="4.0" edition=":server"/>
        <vers num="4.0" edition=":enterprise_server"/>
        <vers num="4.0" edition=":terminal_server"/>
        <vers num="4.0" edition=":workstation"/>
        <vers num="4.0" edition="sp1"/>
        <vers num="4.0" edition="sp1:server"/>
        <vers num="4.0" edition="sp1:workstation"/>
        <vers num="4.0" edition="sp1:terminal_server"/>
        <vers num="4.0" edition="sp1:enterprise_server"/>
        <vers num="4.0" edition="sp2"/>
        <vers num="4.0" edition="sp2:enterprise_server"/>
        <vers num="4.0" edition="sp2:server"/>
        <vers num="4.0" edition="sp2:workstation"/>
        <vers num="4.0" edition="sp2:terminal_server"/>
        <vers num="4.0" edition="sp3"/>
        <vers num="4.0" edition="sp3:workstation"/>
        <vers num="4.0" edition="sp3:server"/>
        <vers num="4.0" edition="sp3:terminal_server"/>
        <vers num="4.0" edition="sp3:enterprise_server"/>
        <vers num="4.0" edition="sp4"/>
        <vers num="4.0" edition="sp4:workstation"/>
        <vers num="4.0" edition="sp4:enterprise_server"/>
        <vers num="4.0" edition="sp4:terminal_server"/>
        <vers num="4.0" edition="sp4:server"/>
        <vers num="4.0" edition="sp5"/>
        <vers num="4.0" edition="sp5:workstation"/>
        <vers num="4.0" edition="sp5:enterprise_server"/>
        <vers num="4.0" edition="sp5:server"/>
        <vers num="4.0" edition="sp5:terminal_server"/>
        <vers num="4.0" edition="sp6"/>
        <vers num="4.0" edition="sp6:terminal_server"/>
        <vers num="4.0" edition="sp6:server"/>
        <vers num="4.0" edition="sp6:enterprise_server"/>
        <vers num="4.0" edition="sp6:workstation"/>
        <vers num="4.0" edition="sp6a"/>
        <vers num="4.0" edition="sp6a:server"/>
        <vers num="4.0" edition="sp6a:enterprise_server"/>
        <vers num="4.0" edition="sp6a:terminal_server"/>
        <vers num="4.0" edition="sp6a:workstation"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":home"/>
        <vers num="" edition=":64-bit"/>
        <vers num="" edition=":embedded"/>
        <vers num="" edition=":media_center"/>
        <vers num="" edition="gold"/>
        <vers num="" edition="gold:professional"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:home"/>
        <vers num="" edition="sp1:media_center"/>
        <vers num="" edition="sp1:64-bit"/>
        <vers num="" edition="sp1:embedded"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:tablet_pc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0035" published="2006-01-11" name="CVE-2006-0035" modified="2012-03-19" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">The netlink_rcv_skb function in af_netlink.c in Linux kernel 2.6.14 and 2.6.15 allows local users to cause a denial of service (infinite loop) via a nlmsg_len field of 0.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.trustix.org/errata/2006/0004" source="TRUSTIX" patch="1">2006-0004</ref>
      <ref url="http://secunia.com/advisories/18482" source="SECUNIA" patch="1" adv="1">18482</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24202" source="XF">kernel-afnetlink-dos(24202)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0220" source="VUPEN" adv="1">ADV-2006-0220</ref>
      <ref url="http://www.securityfocus.com/bid/16414" source="BID">16414</ref>
      <ref url="http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=ad8e4b75c8a7bed475d72ce09bf5267188621961" source="CONFIRM" adv="1">http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=ad8e4b75c8a7bed475d72ce09bf5267188621961</ref>
      <ref url="http://securityreason.com/securityalert/388" source="SREASON">388</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.14"/>
        <vers num="2.6.15"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0036" published="2006-01-23" name="CVE-2006-0036" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">ip_nat_pptp in the PPTP NAT helper (netfilter/ip_nat_helper_pptp.c) in Linux kernel 2.6.14, and other versions, allows remote attackers to cause a denial of service (memory corruption or crash) via an inbound PPTP_IN_CALL_REQUEST packet that causes a null pointer to be used in an offset calculation.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0220" source="VUPEN">ADV-2006-0220</ref>
      <ref url="http://kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=15db34702cfafd24acc60295cf14861e497502ab" source="CONFIRM">http://kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=15db34702cfafd24acc60295cf14861e497502ab</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24203" source="XF">kernel-pptpincallrequest-dos(24203)</ref>
      <ref url="http://www.trustix.org/errata/2006/0004" source="TRUSTIX">2006-0004</ref>
      <ref url="http://www.securityfocus.com/bid/16414" source="BID">16414</ref>
      <ref url="http://securityreason.com/securityalert/388" source="SREASON">388</ref>
      <ref url="http://secunia.com/advisories/18482" source="SECUNIA">18482</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.14"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0037" published="2006-01-23" name="CVE-2006-0037" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">ip_nat_pptp in the PPTP NAT helper (netfilter/ip_nat_helper_pptp.c) in Linux kernel 2.6.14, and other versions, allows local users to cause a denial of service (memory corruption or crash) via a crafted outbound packet that causes an incorrect offset to be calculated from pointer arithmetic when non-linear SKBs (socket buffers) are used.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0220" source="VUPEN">ADV-2006-0220</ref>
      <ref url="http://kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=03b9feca89366952ae5dfe4ad8107b1ece50b710" source="CONFIRM">http://kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=03b9feca89366952ae5dfe4ad8107b1ece50b710</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24204" source="XF">kernel-pptpnathelper-dos(24204)</ref>
      <ref url="http://www.trustix.org/errata/2006/0004" source="TRUSTIX">2006-0004</ref>
      <ref url="http://www.securityfocus.com/bid/16414" source="BID">16414</ref>
      <ref url="http://securityreason.com/securityalert/388" source="SREASON">388</ref>
      <ref url="http://secunia.com/advisories/18482" source="SECUNIA">18482</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.14"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0038" published="2006-03-22" name="CVE-2006-0038" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">Integer overflow in the do_replace function in netfilter for Linux before 2.6.16-rc3, when using "virtualization solutions" such as OpenVZ, allows local users with CAP_NET_ADMIN rights to cause a buffer overflow in the copy_from_user function.</descript>
    </desc>
    <sols>
      <sol source="nvd">Linux kernel version 2.6.16 has been released to address this issue.</sol>
    </sols>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17178" source="BID" patch="1">17178</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=186295" source="CONFIRM">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=186295</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25400" source="XF">linux-netfilter-doreplace-overflow(25400)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2554" source="VUPEN">ADV-2006-2554</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1046" source="VUPEN">ADV-2006-1046</ref>
      <ref url="http://www.ubuntu.com/usn/usn-302-1" source="UBUNTU">USN-302-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0575.html" source="REDHAT">RHSA-2006:0575</ref>
      <ref url="http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=ee4bb818ae35f68d1f848eae0a7b150a38eb4168" source="CONFIRM">http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=ee4bb818ae35f68d1f848eae0a7b150a38eb4168</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1103" source="DEBIAN">DSA-1103</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1097" source="DEBIAN">DSA-1097</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-200.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-200.htm</ref>
      <ref url="http://secunia.com/advisories/22417" source="SECUNIA">22417</ref>
      <ref url="http://secunia.com/advisories/21465" source="SECUNIA">21465</ref>
      <ref url="http://secunia.com/advisories/20914" source="SECUNIA">20914</ref>
      <ref url="http://secunia.com/advisories/20716" source="SECUNIA">20716</ref>
      <ref url="http://secunia.com/advisories/20671" source="SECUNIA">20671</ref>
      <ref url="http://secunia.com/advisories/19330" source="SECUNIA">19330</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10945" source="OVAL">oval:org.mitre.oval:def:10945</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0" edition="test1"/>
        <vers num="2.6.0" edition="test10"/>
        <vers num="2.6.0" edition="test11"/>
        <vers num="2.6.0" edition="test2"/>
        <vers num="2.6.0" edition="test3"/>
        <vers num="2.6.0" edition="test4"/>
        <vers num="2.6.0" edition="test5"/>
        <vers num="2.6.0" edition="test6"/>
        <vers num="2.6.0" edition="test7"/>
        <vers num="2.6.0" edition="test8"/>
        <vers num="2.6.0" edition="test9"/>
        <vers num="2.6.1" edition="rc1"/>
        <vers num="2.6.1" edition="rc2"/>
        <vers num="2.6.10" edition="rc2"/>
        <vers num="2.6.11" edition="rc2"/>
        <vers num="2.6.11" edition="rc3"/>
        <vers num="2.6.11" edition="rc4"/>
        <vers num="2.6.11.11"/>
        <vers num="2.6.11.12"/>
        <vers num="2.6.11.5"/>
        <vers num="2.6.11.6"/>
        <vers num="2.6.11.7"/>
        <vers num="2.6.11.8"/>
        <vers num="2.6.12" edition="rc1"/>
        <vers num="2.6.12" edition="rc4"/>
        <vers num="2.6.12" edition="rc5"/>
        <vers num="2.6.12.1"/>
        <vers num="2.6.12.2"/>
        <vers num="2.6.12.3"/>
        <vers num="2.6.12.4"/>
        <vers num="2.6.12.5"/>
        <vers num="2.6.12.6"/>
        <vers num="2.6.13" edition="rc1"/>
        <vers num="2.6.13" edition="rc4"/>
        <vers num="2.6.13" edition="rc6"/>
        <vers num="2.6.13" edition="rc7"/>
        <vers num="2.6.13.1"/>
        <vers num="2.6.13.2"/>
        <vers num="2.6.13.3"/>
        <vers num="2.6.13.4"/>
        <vers num="2.6.14" edition="rc1"/>
        <vers num="2.6.14" edition="rc2"/>
        <vers num="2.6.14" edition="rc3"/>
        <vers num="2.6.14" edition="rc4"/>
        <vers num="2.6.14.1"/>
        <vers num="2.6.14.2"/>
        <vers num="2.6.14.3"/>
        <vers num="2.6.14.4"/>
        <vers num="2.6.14.5"/>
        <vers num="2.6.15" edition="rc1"/>
        <vers num="2.6.15" edition="rc2"/>
        <vers num="2.6.15" edition="rc3"/>
        <vers num="2.6.15.1"/>
        <vers num="2.6.15.2"/>
        <vers num="2.6.15.3"/>
        <vers num="2.6.15.4"/>
        <vers num="2.6.15.5"/>
        <vers num="2.6.16" edition="rc1"/>
        <vers num="2.6.2"/>
        <vers num="2.6.3"/>
        <vers num="2.6.4"/>
        <vers num="2.6.5"/>
        <vers num="2.6.6" edition="rc1"/>
        <vers num="2.6.7" edition="rc1"/>
        <vers num="2.6.8" edition="rc1"/>
        <vers num="2.6.8" edition="rc2"/>
        <vers num="2.6.8" edition="rc3"/>
        <vers num="2.6.9" edition="2.6.20"/>
        <vers num="2.6_test9_cvs"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0039" published="2006-05-19" name="CVE-2006-0039" modified="2011-03-07" discovered="2006-05-16" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:N/A:C)" CVSS_score="4.7" CVSS_impact_subscore="7.8" CVSS_exploit_subscore="1.9" CVSS_base_score="4.7">
    <desc>
      <descript source="cve">Race condition in the do_add_counters function in netfilter for Linux kernel 2.6.16 allows local users with CAP_NET_ADMIN capabilities to read kernel memory by triggering the race condition in a way that produces a size value that is inconsistent with allocated memory, which leads to a buffer over-read in IPT_ENTRY_ITERATE.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
      <race/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=2722971cbe831117686039d5c334f2c0f560be13" source="MISC" patch="1">http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=2722971cbe831117686039d5c334f2c0f560be13</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=133465" source="CONFIRM" patch="1">http://bugs.gentoo.org/show_bug.cgi?id=133465</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=191698" source="CONFIRM">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=191698</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26583" source="XF">linux-doaddcounters-race-condition(26583)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2554" source="VUPEN">ADV-2006-2554</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1893" source="VUPEN">ADV-2006-1893</ref>
      <ref url="http://www.ubuntu.com/usn/usn-311-1" source="UBUNTU">USN-311-1</ref>
      <ref url="http://www.securityfocus.com/bid/18113" source="BID">18113</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0689.html" source="REDHAT">RHSA-2006:0689</ref>
      <ref url="http://www.osvdb.org/25697" source="OSVDB">25697</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1103" source="DEBIAN">DSA-1103</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1097" source="DEBIAN">DSA-1097</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-249.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-249.htm</ref>
      <ref url="http://secunia.com/advisories/22945" source="SECUNIA">22945</ref>
      <ref url="http://secunia.com/advisories/22292" source="SECUNIA">22292</ref>
      <ref url="http://secunia.com/advisories/21476" source="SECUNIA">21476</ref>
      <ref url="http://secunia.com/advisories/20991" source="SECUNIA">20991</ref>
      <ref url="http://secunia.com/advisories/20914" source="SECUNIA">20914</ref>
      <ref url="http://secunia.com/advisories/20671" source="SECUNIA">20671</ref>
      <ref url="http://secunia.com/advisories/20185" source="SECUNIA">20185</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10309" source="OVAL">oval:org.mitre.oval:def:10309</ref>
      <ref url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.17" source="CONFIRM">http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.17</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.16"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0040" published="2006-03-09" name="CVE-2006-0040" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">GNOME Evolution 2.4.2.1 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via a text e-mail with a large number of URLs, possibly due to unknown problems in gtkhtml.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0801" source="VUPEN">ADV-2006-0801</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426452/100/0/threaded" source="BUGTRAQ">20060301 Evolution Emailer DoS</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25050" source="XF">evolution-email-dos(25050)</ref>
      <ref url="http://www.securityfocus.com/bid/16899" source="BID">16899</ref>
      <ref url="http://secunia.com/advisories/19094" source="SECUNIA">19094</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnome" name="evolution">
        <vers num="2.4.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0042" published="2006-02-18" name="CVE-2006-0042" modified="2011-05-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in (1) apreq_parse_headers and (2) apreq_parse_urlencoded functions in Apache2::Request (Libapreq2) before 2.07 allows remote attackers cause a denial of service (CPU consumption) via unknown attack vectors that result in quadratic computational complexity.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16710" source="BID" patch="1">16710</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1000" source="DEBIAN" patch="1" adv="1">DSA-1000</ref>
      <ref url="http://secunia.com/advisories/19139" source="SECUNIA" patch="1" adv="1">19139</ref>
      <ref url="http://secunia.com/advisories/18846" source="SECUNIA" patch="1" adv="1">18846</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24917" source="XF">libapreq2-parsing-dos(24917)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0645" source="VUPEN" adv="1">ADV-2006-0645</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-08.xml" source="GENTOO">GLSA-200604-08</ref>
      <ref url="http://svn.apache.org/viewcvs.cgi/httpd/apreq/tags/v2_07/CHANGES?rev=376998&amp;view=markup" source="CONFIRM">http://svn.apache.org/viewcvs.cgi/httpd/apreq/tags/v2_07/CHANGES?rev=376998&amp;view=markup</ref>
      <ref url="http://securityreason.com/securityalert/737" source="SREASON">737</ref>
      <ref url="http://secunia.com/advisories/19658" source="SECUNIA" adv="1">19658</ref>
    </refs>
    <vuln_soft>
      <prod vendor="libapreq2" name="libapreq2">
        <vers num="1.0"/>
        <vers num="1.1"/>
        <vers num="1.2"/>
        <vers num="1.3"/>
        <vers num="1.33"/>
        <vers num="2.01_dev"/>
        <vers num="2.02_dev"/>
        <vers num="2.03_dev"/>
        <vers num="2.04_dev"/>
        <vers num="2.05_dev"/>
        <vers num="2.06_dev"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0043" published="2006-01-30" name="CVE-2006-0043" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in the realpath function in nfs-server rpc.mountd, as used in SUSE Linux 9.1 through 10.0, allows local users to execute arbitrary code via unspecified vectors involving mount requests and symlinks.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18638" source="SECUNIA" patch="1" adv="1">18638</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2006-Jan/0007.html" source="SUSE" patch="1" adv="1">SUSE-SA:2006:005</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24347" source="XF">nfs-rpcmountd-realpath-bo(24347)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0348" source="VUPEN">ADV-2006-0348</ref>
      <ref url="http://www.securityfocus.com/bid/16388" source="BID">16388</ref>
      <ref url="http://secunia.com/advisories/18614" source="SECUNIA" adv="1">18614</ref>
      <ref url="http://www.debian.org/security/2006/dsa-975" source="DEBIAN">DSA-975</ref>
      <ref url="http://secunia.com/advisories/18889" source="SECUNIA">18889</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=350020" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=350020</ref>
    </refs>
    <vuln_soft>
      <prod vendor="suse" name="suse_linux">
        <vers num="1.0"/>
        <vers num="10.0" edition=""/>
        <vers num="10.0" edition=":professional"/>
        <vers num="9.1" edition=""/>
        <vers num="9.1" edition=":personal"/>
        <vers num="9.1" edition=":professional"/>
        <vers num="9.1" edition=":x86_64"/>
        <vers num="9.2" edition=""/>
        <vers num="9.2" edition=":professional"/>
        <vers num="9.2" edition=":personal"/>
        <vers num="9.2" edition=":x86_64"/>
        <vers num="9.3" edition=""/>
        <vers num="9.3" edition=":x86_64"/>
        <vers num="9.3" edition=":personal"/>
        <vers num="9.3" edition=":professional"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0044" published="2006-01-17" name="CVE-2006-0044" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in context.py in Albatross web application toolkit before 1.33 allows remote attackers to execute arbitrary commands via unspecified vectors involving template files and the "handling of submitted form fields".</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2006/dsa-942" source="DEBIAN" patch="1" adv="1">DSA-942</ref>
      <ref url="http://secunia.com/advisories/18457" source="SECUNIA" patch="1" adv="1">18457</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0196" source="VUPEN">ADV-2006-0196</ref>
      <ref url="http://www.securityfocus.com/bid/16252" source="BID">16252</ref>
      <ref url="http://www.object-craft.com.au/projects/albatross/news.html" source="CONFIRM">http://www.object-craft.com.au/projects/albatross/news.html</ref>
      <ref url="http://security.debian.org/pool/updates/main/a/albatross/albatross_1.20-2.diff.gz" source="MISC">http://security.debian.org/pool/updates/main/a/albatross/albatross_1.20-2.diff.gz</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24130" source="XF">albatross-context-command-execution(24130)</ref>
      <ref url="http://www.osvdb.org/22451" source="OSVDB">22451</ref>
      <ref url="http://secunia.com/advisories/18496" source="SECUNIA">18496</ref>
    </refs>
    <vuln_soft>
      <prod vendor="albatross" name="albatross">
        <vers num="1.00"/>
        <vers num="1.01"/>
        <vers num="1.10"/>
        <vers num="1.20"/>
        <vers num="1.30"/>
        <vers num="1.32"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0045" published="2006-01-20" name="CVE-2006-0045" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">crawl before 4.0.0 does not securely call programs when saving and loading games, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2006/dsa-949" source="DEBIAN" patch="1" adv="1">DSA-949</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0303" source="VUPEN">ADV-2006-0303</ref>
      <ref url="http://www.securityfocus.com/bid/16337" source="BID">16337</ref>
      <ref url="http://secunia.com/advisories/18545" source="SECUNIA" adv="1">18545</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24262" source="XF">crawl-insecure-command-execution(24262)</ref>
      <ref url="http://www.osvdb.org/22690" source="OSVDB">22690</ref>
      <ref url="http://secunia.com/advisories/18573" source="SECUNIA">18573</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linley_henzell" name="dungeon_crawl">
        <vers num="4.0.0_b23"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0046" published="2006-02-13" name="CVE-2006-0046" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">squid_redirect script in adzapper before 2006-01-29 allows remote attackers to cause a denial of service (CPU consumption) via a URL with a large number of trailing / (forward slashes), which might produce inefficient regular expressions.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2006/dsa-966" source="DEBIAN" patch="1" adv="1">DSA-966</ref>
      <ref url="http://secunia.com/advisories/18777" source="SECUNIA" patch="1" adv="1">18777</ref>
      <ref url="http://secunia.com/advisories/18771" source="SECUNIA" patch="1" adv="1">18771</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0491" source="VUPEN">ADV-2006-0491</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=350308" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=350308</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi/squid_redirect.diff?bug=350308;msg=5;att=1" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi/squid_redirect.diff?bug=350308;msg=5;att=1</ref>
      <ref url="http://adzapper.sourceforge.net/cvslog.html" source="CONFIRM">http://adzapper.sourceforge.net/cvslog.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24640" source="XF">adzapper-squid-redirect-dos(24640)</ref>
      <ref url="http://www.securityfocus.com/bid/16558" source="BID">16558</ref>
      <ref url="http://www.osvdb.org/22900" source="OSVDB">22900</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cameron_simpson" name="adzapper">
        <vers num="2006-01-01"/>
        <vers num="2006-01-05"/>
        <vers num="2006-01-07"/>
        <vers num="2006-01-14"/>
        <vers num="2006-01-15"/>
        <vers num="2006-01-23"/>
        <vers num="2006-01-24"/>
        <vers num="2006-01-25"/>
        <vers num="2006-01-28"/>
        <vers num="2006-01-29"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0047" published="2006-03-07" name="CVE-2006-0047" modified="2011-08-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">packets.c in Freeciv 2.0 before 2.0.8 allows remote attackers to cause a denial of service (server crash) via crafted packets with negative compressed size values.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16975" source="BID" patch="1">16975</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/426866/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20060306 Out of memory crash in Freeciv 2.0.7</ref>
      <ref url="http://secunia.com/advisories/19120" source="SECUNIA" patch="1" adv="1">19120</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25166" source="XF">freeciv-packets-dos(25166)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0838" source="VUPEN" adv="1">ADV-2006-0838</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:053" source="MANDRIVA">MDKSA-2006:053</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200603-11.xml" source="GENTOO">GLSA-200603-11</ref>
      <ref url="http://www.debian.org/security/2006/dsa-994" source="DEBIAN">DSA-994</ref>
      <ref url="http://secunia.com/advisories/19253" source="SECUNIA" adv="1">19253</ref>
      <ref url="http://secunia.com/advisories/19227" source="SECUNIA" adv="1">19227</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=355211" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=355211</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freeciv" name="freeciv">
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.7a"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0048" published="2006-04-25" name="CVE-2006-0048" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Francesco Stablum tcpick 0.2.1 allows remote attackers to cause a denial of service (segmentation fault) via certain fragmented packets, possibly involving invalid headers and an attacker-controlled payload length.  NOTE: this issue might be a buffer overflow or overread.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/1466" source="VUPEN">ADV-2006-1466</ref>
      <ref url="http://www.securityfocus.com/bid/17665" source="BID">17665</ref>
      <ref url="http://sourceforge.net/mailarchive/forum.php?thread_id=9989610&amp;forum_id=37151" source="MISC">http://sourceforge.net/mailarchive/forum.php?thread_id=9989610&amp;forum_id=37151</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26090" source="XF">tcpick-writec-dos(26090)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francesco_stablum" name="tcpick">
        <vers num="0.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0049" published="2006-03-13" name="CVE-2006-0049" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">gpg in GnuPG before 1.4.2.2 does not properly verify non-detached signatures, which allows attackers to inject unsigned data via a data packet that is not associated with a control packet, which causes the check for concatenated signatures to report that the signature is valid, a different vulnerability than CVE-2006-0455.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17058" source="BID" patch="1">17058</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427324/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20060309 GnuPG does not detect injection of unsigned data</ref>
      <ref url="http://www.osvdb.org/23790" source="OSVDB" patch="1">23790</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200603-08.xml" source="GENTOO" patch="1" adv="1">GLSA-200603-08</ref>
      <ref url="http://www.debian.org/security/2006/dsa-993" source="DEBIAN" patch="1" adv="1">DSA-993</ref>
      <ref url="http://securitytracker.com/id?1015749" source="SECTRACK" patch="1">1015749</ref>
      <ref url="http://secunia.com/advisories/19173" source="SECUNIA" patch="1" adv="1">19173</ref>
      <ref url="http://lists.gnupg.org/pipermail/gnupg-announce/2006q1/000216.html" source="MLIST" patch="1" adv="1">[gnupg-announce] 20060309 [Announce] GnuPG does not detect injection of unsigned data</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0915" source="VUPEN">ADV-2006-0915</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-264-1" source="UBUNTU">USN-264-1</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10063" source="OVAL">oval:org.mitre.oval:def:10063</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25184" source="XF">gnupg-nondetached-sig-verification(25184)</ref>
      <ref url="http://www.trustix.org/errata/2006/0014" source="TRUSTIX">2006-0014</ref>
      <ref url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.476477" source="SLACKWARE">SSA:2006-072-02</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/433931/100/0/threaded" source="FEDORA">FLSA-2006:185355</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0266.html" source="REDHAT">RHSA-2006:0266</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-March/msg00021.html" source="FEDORA">FEDORA-2006-147</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:055" source="MANDRIVA">MDKSA-2006:055</ref>
      <ref url="http://securityreason.com/securityalert/568" source="SREASON">568</ref>
      <ref url="http://securityreason.com/securityalert/450" source="SREASON">450</ref>
      <ref url="http://secunia.com/advisories/19532" source="SECUNIA">19532</ref>
      <ref url="http://secunia.com/advisories/19287" source="SECUNIA">19287</ref>
      <ref url="http://secunia.com/advisories/19249" source="SECUNIA">19249</ref>
      <ref url="http://secunia.com/advisories/19244" source="SECUNIA">19244</ref>
      <ref url="http://secunia.com/advisories/19234" source="SECUNIA">19234</ref>
      <ref url="http://secunia.com/advisories/19232" source="SECUNIA">19232</ref>
      <ref url="http://secunia.com/advisories/19231" source="SECUNIA">19231</ref>
      <ref url="http://secunia.com/advisories/19203" source="SECUNIA">19203</ref>
      <ref url="http://secunia.com/advisories/19197" source="SECUNIA">19197</ref>
      <ref url="http://lists.suse.de/archive/suse-security-announce/2006-Mar/0003.html" source="SUSE">SUSE-SA:2006:014</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060401-01-U" source="SGI">20060401-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="privacy_guard">
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.3b"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.2"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2" edition="rc1"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.2.6"/>
        <vers num="1.2.7"/>
        <vers num="1.3.3"/>
        <vers num="1.3.4"/>
        <vers num="1.4"/>
        <vers num="1.4.1"/>
        <vers num="1.4.2"/>
        <vers num="1.4.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0050" published="2006-03-23" name="CVE-2006-0050" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">snmptrapfmt in Debian 3.0 allows local users to overwrite arbitrary files via a symlink attack on a temporary log file.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
      <race/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2006/dsa-1013" source="DEBIAN" patch="1" adv="1">DSA-1013</ref>
      <ref url="http://secunia.com/advisories/19318" source="SECUNIA" patch="1" adv="1">19318</ref>
      <ref url="http://www.securityfocus.com/bid/17182" source="BID">17182</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25442" source="XF">snmptrapfmt-log-temprary-file(25442)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="debian_linux">
        <vers num="3.0" edition=""/>
        <vers num="3.0" edition=":mips"/>
        <vers num="3.0" edition=":ia-32"/>
        <vers num="3.0" edition=":s-390"/>
        <vers num="3.0" edition=":alpha"/>
        <vers num="3.0" edition=":arm"/>
        <vers num="3.0" edition=":mipsel"/>
        <vers num="3.0" edition=":ppc"/>
        <vers num="3.0" edition=":hppa"/>
        <vers num="3.0" edition=":m68k"/>
        <vers num="3.0" edition=":ia-64"/>
        <vers num="3.0" edition=":sparc"/>
        <vers num="3.1" edition=""/>
        <vers num="3.1" edition=":sparc"/>
        <vers num="3.1" edition=":ia-64"/>
        <vers num="3.1" edition=":s-390"/>
        <vers num="3.1" edition=":mipsel"/>
        <vers num="3.1" edition=":ppc"/>
        <vers num="3.1" edition=":mips"/>
        <vers num="3.1" edition=":hppa"/>
        <vers num="3.1" edition=":m68k"/>
        <vers num="3.1" edition=":alpha"/>
        <vers num="3.1" edition=":arm"/>
        <vers num="3.1" edition=":amd64"/>
        <vers num="3.1" edition=":ia-32"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0051" published="2006-04-05" name="CVE-2006-0051" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Buffer overflow in playlistimport.cpp in Kaffeine Player 0.4.2 through 0.7.1 allows user-assisted attackers to execute arbitrary code via long HTTP request headers when Kaffeine is "fetching remote playlists", which triggers the overflow in the http_peek function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.kde.org/info/security/advisory-20060404-1.txt" source="CONFIRM" patch="1" adv="1">http://www.kde.org/info/security/advisory-20060404-1.txt</ref>
      <ref url="http://secunia.com/advisories/19525" source="SECUNIA" patch="1" adv="1">19525</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25631" source="XF">kaffeine-http-peek-bo(25631)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1229" source="VUPEN">ADV-2006-1229</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-268-1" source="UBUNTU">USN-268-1</ref>
      <ref url="http://www.securityfocus.com/bid/17372" source="BID">17372</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430319/100/0/threaded" source="BUGTRAQ">20060405 [Kaffeine Security Advisory] Heap based buffer overflow in http_peek()</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_08_sr.html" source="SUSE">SUSE-SR:2006:008</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-04.xml" source="GENTOO">GLSA-200604-04</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1023" source="DEBIAN">DSA-1023</ref>
      <ref url="http://securitytracker.com/id?1015863" source="SECTRACK">1015863</ref>
      <ref url="http://secunia.com/advisories/19571" source="SECUNIA">19571</ref>
      <ref url="http://secunia.com/advisories/19557" source="SECUNIA">19557</ref>
      <ref url="http://secunia.com/advisories/19549" source="SECUNIA">19549</ref>
      <ref url="http://secunia.com/advisories/19542" source="SECUNIA">19542</ref>
      <ref url="http://secunia.com/advisories/19540" source="SECUNIA">19540</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:065" source="MANDRIVA">MDKSA-2006:065</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kaffeine" name="kaffeine_player">
        <vers num="0.4.2"/>
        <vers num="0.4.3"/>
        <vers num="0.4.3b"/>
        <vers num="0.5_rc1"/>
        <vers num="0.7.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0052" published="2006-03-31" name="CVE-2006-0052" modified="2010-08-21" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The attachment scrubber (Scrubber.py) in Mailman 2.1.5 and earlier, when using Python's library email module 2.5, allows remote attackers to cause a denial of service (mailing list delivery failure) via a multipart MIME message with a single part that has two blank lines between the first boundary and the end boundary.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17311" source="BID" patch="1">17311</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=358892" source="CONFIRM" patch="1">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=358892</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9475" source="OVAL">oval:org.mitre.oval:def:9475</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-267-1" source="UBUNTU">USN-267-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0486.html" source="REDHAT">RHSA-2006:0486</ref>
      <ref url="http://www.osvdb.org/24367" source="OSVDB">24367</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_08_sr.html" source="SUSE">SUSE-SR:2006:008</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:061" source="MANDRIVA">MDKSA-2006:061</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1027" source="DEBIAN">DSA-1027</ref>
      <ref url="http://securitytracker.com/id?1015851" source="SECTRACK">1015851</ref>
      <ref url="http://secunia.com/advisories/20782" source="SECUNIA">20782</ref>
      <ref url="http://secunia.com/advisories/20624" source="SECUNIA">20624</ref>
      <ref url="http://secunia.com/advisories/19571" source="SECUNIA">19571</ref>
      <ref url="http://secunia.com/advisories/19545" source="SECUNIA">19545</ref>
      <ref url="http://secunia.com/advisories/19522" source="SECUNIA">19522</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060602-01-U.asc" source="SGI">20060602-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="mailman">
        <vers num="1.0"/>
        <vers num="1.1"/>
        <vers num="2.0" edition="beta3"/>
        <vers num="2.0" edition="beta4"/>
        <vers num="2.0" edition="beta5"/>
        <vers num="2.0.1"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.12"/>
        <vers num="2.0.13"/>
        <vers num="2.0.14"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.7"/>
        <vers num="2.0.8"/>
        <vers num="2.0.9"/>
        <vers num="2.1"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.1.3"/>
        <vers num="2.1.4"/>
        <vers num="2.1.5"/>
        <vers num="2.1b1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0053" published="2006-04-10" name="CVE-2006-0053" modified="2011-05-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Imager (libimager-perl) before 0.50 allows user-assisted attackers to cause a denial of service (segmentation fault) by writing a 2- or 4-channel JPEG image (or a 2-channel TGA image) to a scalar, which triggers a NULL pointer dereference.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17415" source="BID" patch="1">17415</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1028" source="DEBIAN" patch="1" adv="1">DSA-1028</ref>
      <ref url="http://secunia.com/advisories/19577" source="SECUNIA" patch="1" adv="1">19577</ref>
      <ref url="http://secunia.com/advisories/19575" source="SECUNIA" patch="1" adv="1">19575</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25717" source="XF">imager-jpeg-tga-dos(25717)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1294" source="VUPEN" adv="1">ADV-2006-1294</ref>
      <ref url="http://rt.cpan.org/Public/Bug/Display.html?id=18397" source="MISC">http://rt.cpan.org/Public/Bug/Display.html?id=18397</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=359661" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=359661</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tony_cook" name="imager">
        <vers num="0.41"/>
        <vers num="0.42"/>
        <vers num="0.43"/>
        <vers num="0.44_1"/>
        <vers num="0.45"/>
        <vers num="0.45_2"/>
        <vers num="0.47"/>
        <vers num="0.48"/>
        <vers num="0.49"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0054" published="2006-01-11" name="CVE-2006-0054" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The ipfw firewall in FreeBSD 6.0-RELEASE allows remote attackers to cause a denial of service (firewall crash) via ICMP IP fragments that match a reset, reject or unreach action, which leads to an access of an uninitialized pointer.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16209" source="BID" patch="1">16209</ref>
      <ref url="http://secunia.com/advisories/18378" source="SECUNIA" patch="1" adv="1">18378</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:04.ipfw.asc" source="FREEBSD">FreeBSD-SA-06:04</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24073" source="XF">ipfw-icmp-fragment-dos(24073)</ref>
      <ref url="http://www.osvdb.org/22319" source="OSVDB">22319</ref>
      <ref url="http://securitytracker.com/id?1015477" source="SECTRACK">1015477</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="6.0" edition="release"/>
        <vers num="6.0" edition="stable"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0055" published="2006-01-11" name="CVE-2006-0055" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The ispell_op function in ee on FreeBSD 4.10 to 6.0 uses predictable filenames and does not confirm which file is being written, which allows local users to overwrite arbitrary files via a symlink attack when ee invokes ispell.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16207" source="BID" patch="1">16207</ref>
      <ref url="http://secunia.com/advisories/18404" source="SECUNIA" patch="1" adv="1">18404</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:02.ee.asc" source="FREEBSD">FreeBSD-SA-06:02</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24074" source="XF">ee-ispell-op-symlink(24074)</ref>
      <ref url="http://www.osvdb.org/22320" source="OSVDB">22320</ref>
      <ref url="http://securitytracker.com/id?1015469" source="SECTRACK">1015469</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="4.10" edition="release"/>
        <vers num="4.10" edition="release_p8"/>
        <vers num="4.10" edition="releng"/>
        <vers num="4.11" edition="release_p3"/>
        <vers num="4.11" edition="releng"/>
        <vers num="4.11" edition="stable"/>
        <vers num="5.0" edition="alpha"/>
        <vers num="5.0" edition="release_p14"/>
        <vers num="5.0" edition="releng"/>
        <vers num="5.1" edition="alpha"/>
        <vers num="5.1" edition="release"/>
        <vers num="5.1" edition="release_p5"/>
        <vers num="5.1" edition="releng"/>
        <vers num="5.2"/>
        <vers num="5.2.1" edition="release"/>
        <vers num="5.2.1" edition="releng"/>
        <vers num="5.3" edition="release"/>
        <vers num="5.3" edition="releng"/>
        <vers num="5.3" edition="stable"/>
        <vers num="5.4" edition="pre-release"/>
        <vers num="5.4" edition="release"/>
        <vers num="5.4" edition="releng"/>
        <vers num="6.0" edition="release"/>
        <vers num="6.0" edition="stable"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0056" published="2006-02-13" name="CVE-2006-0056" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Double free vulnerability in the authentication and authentication token alteration code in PAM-MySQL 0.6.x before 0.6.2 and 0.7.x before 0.7pre3 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted passwords, which lead to a double free of a pointer that was created by the pam_get_item function.  NOTE: this issue only occurs in certain configurations in which there are multiple PAM modules, PAM-MySQL is not evaluated first, and there are no requisite modules before PAM-MySQL.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/693909" source="CERT-VN" patch="1" adv="1">VU#693909</ref>
      <ref url="http://www.securityfocus.com/bid/16564" source="BID" patch="1">16564</ref>
      <ref url="http://securitytracker.com/id?1015603" source="SECTRACK" patch="1">1015603</ref>
      <ref url="http://secunia.com/advisories/18598" source="SECUNIA" patch="1" adv="1">18598</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0490" source="VUPEN">ADV-2006-0490</ref>
      <ref url="http://www.osvdb.org/22995" source="OSVDB">22995</ref>
      <ref url="http://www.osvdb.org/22994" source="OSVDB">22994</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200606-18.xml" source="GENTOO">GLSA-200606-18</ref>
      <ref url="http://sourceforge.net/forum/forum.php?forum_id=499394" source="CONFIRM">http://sourceforge.net/forum/forum.php?forum_id=499394</ref>
      <ref url="http://secunia.com/advisories/20690" source="SECUNIA" adv="1">20690</ref>
      <ref url="http://jvn.jp/cert/JVNVU%23693909/index.html" source="MISC">http://jvn.jp/cert/JVNVU%23693909/index.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pam-mysql" name="pam-mysql">
        <vers num="0.1"/>
        <vers num="0.2"/>
        <vers num="0.3"/>
        <vers num="0.4"/>
        <vers num="0.4.7"/>
        <vers num="0.5"/>
        <vers num="0.6"/>
        <vers num="0.7_pre1"/>
        <vers num="0.7_pre2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0057" published="2006-01-27" name="CVE-2006-0057" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to bypass the Kill bit settings for dangerous ActiveX controls via unknown vectors involving crafted HTML, which can expose the browser to attacks that would otherwise be prevented by the Kill bit setting. NOTE: CERT/CC claims that MS05-054 fixes this issue, but it is not described in MS05-054.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/998297" source="CERT-VN" adv="1">VU#998297</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms05-054.mspx" source="MISC" patch="1" adv="1">http://www.microsoft.com/technet/security/bulletin/ms05-054.mspx</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24379" source="XF">ie-activex-killbit-bypass(24379)</ref>
      <ref url="http://www.securityfocus.com/bid/16409" source="BID">16409</ref>
      <ref url="http://www.osvdb.org/23657" source="OSVDB">23657</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.01" edition="sp4"/>
        <vers num="5.5" edition="sp2"/>
        <vers num="6" edition="sp1"/>
        <vers num="6" edition="windows_server_2003_sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0058" published="2006-03-22" name="CVE-2006-0058" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Signal handler race condition in Sendmail 8.13.x before 8.13.6 allows remote attackers to execute arbitrary code by triggering timeouts in a way that causes the setjmp and longjmp function calls to be interrupted and modify unexpected memory locations.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <race/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-081A.html" source="CERT">TA06-081A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/834865" source="CERT-VN">VU#834865</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0265.html" source="REDHAT" patch="1" adv="1">RHSA-2006:0265</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0264.html" source="REDHAT" patch="1" adv="1">RHSA-2006:0264</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2490" source="VUPEN">ADV-2006-2490</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2189" source="VUPEN">ADV-2006-2189</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1529" source="VUPEN">ADV-2006-1529</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1157" source="VUPEN">ADV-2006-1157</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1139" source="VUPEN">ADV-2006-1139</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1072" source="VUPEN">ADV-2006-1072</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1068" source="VUPEN">ADV-2006-1068</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1051" source="VUPEN">ADV-2006-1051</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1049" source="VUPEN">ADV-2006-1049</ref>
      <ref url="http://www.sendmail.com/company/advisory/index.shtml" source="CONFIRM">http://www.sendmail.com/company/advisory/index.shtml</ref>
      <ref url="http://www.securityfocus.com/archive/1/428536/100/0/threaded" source="BUGTRAQ">20060322 sendmail vuln advisories (CVE-2006-0058)</ref>
      <ref url="http://www.openpkg.org/security/advisories/OpenPKG-SA-2006.007-sendmail.html" source="OPENPKG">OpenPKG-SA-2006.007</ref>
      <ref url="http://www.iss.net/threats/216.html" source="ISS">20060322 Sendmail Remote Signal Handling Vulnerability</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200603-21.xml" source="GENTOO">GLSA-200603-21</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1015" source="DEBIAN">DSA-1015</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-200494-1" source="SUNALERT">200494</ref>
      <ref url="http://secunia.com/advisories/19367" source="SECUNIA">19367</ref>
      <ref url="http://secunia.com/advisories/19363" source="SECUNIA">19363</ref>
      <ref url="http://secunia.com/advisories/19342" source="SECUNIA">19342</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11074" source="OVAL">oval:org.mitre.oval:def:11074</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=c00692635" source="HP">HPSBTU02116</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00629555" source="HP">HPSBUX02108</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24584" source="XF">smtp-timeout-bo(24584)</ref>
      <ref url="http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&amp;ID=2751" source="CONFIRM">http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&amp;ID=2751</ref>
      <ref url="http://www14.software.ibm.com/webapp/set2/sas/f/hmc/power5/install/v52.Readme.html#MH00688" source="CONFIRM">http://www14.software.ibm.com/webapp/set2/sas/f/hmc/power5/install/v52.Readme.html#MH00688</ref>
      <ref url="http://www.securityfocus.com/bid/17192" source="BID">17192</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/428656/100/0/threaded" source="FEDORA">FLSA:186277</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00018.html" source="FEDORA">FEDORA-2006-193</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-April/msg00017.html" source="FEDORA">FEDORA-2006-194</ref>
      <ref url="http://www.osvdb.org/24037" source="OSVDB">24037</ref>
      <ref url="http://www.openbsd.org/errata38.html#sendmail" source="OPENBSD">[3.8] 006: SECURITY FIX: March 25, 2006</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_17_sendmail.html" source="SUSE">SUSE-SA:2006:017</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:058" source="MANDRIVA">MDKSA-2006:058</ref>
      <ref url="http://www.f-secure.com/security/fsc-2006-2.shtml" source="CONFIRM">http://www.f-secure.com/security/fsc-2006-2.shtml</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/q-151.shtml" source="CIAC">Q-151</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY82994&amp;apar=only" source="AIXAPAR">IY82994</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY82993&amp;apar=only" source="AIXAPAR">IY82993</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY82992&amp;apar=only" source="AIXAPAR">IY82992</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-078.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-078.htm</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-074.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-074.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102324-1" source="SUNALERT">102324</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102262-1" source="SUNALERT">102262</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.619600" source="SLACKWARE">SSA:2006-081-01</ref>
      <ref url="http://securitytracker.com/id?1015801" source="SECTRACK">1015801</ref>
      <ref url="http://securityreason.com/securityalert/743" source="SREASON">743</ref>
      <ref url="http://securityreason.com/securityalert/612" source="SREASON">612</ref>
      <ref url="http://secunia.com/advisories/20723" source="SECUNIA">20723</ref>
      <ref url="http://secunia.com/advisories/20243" source="SECUNIA">20243</ref>
      <ref url="http://secunia.com/advisories/19774" source="SECUNIA">19774</ref>
      <ref url="http://secunia.com/advisories/19676" source="SECUNIA">19676</ref>
      <ref url="http://secunia.com/advisories/19533" source="SECUNIA">19533</ref>
      <ref url="http://secunia.com/advisories/19532" source="SECUNIA">19532</ref>
      <ref url="http://secunia.com/advisories/19466" source="SECUNIA">19466</ref>
      <ref url="http://secunia.com/advisories/19450" source="SECUNIA">19450</ref>
      <ref url="http://secunia.com/advisories/19407" source="SECUNIA">19407</ref>
      <ref url="http://secunia.com/advisories/19404" source="SECUNIA">19404</ref>
      <ref url="http://secunia.com/advisories/19394" source="SECUNIA">19394</ref>
      <ref url="http://secunia.com/advisories/19368" source="SECUNIA">19368</ref>
      <ref url="http://secunia.com/advisories/19361" source="SECUNIA">19361</ref>
      <ref url="http://secunia.com/advisories/19360" source="SECUNIA">19360</ref>
      <ref url="http://secunia.com/advisories/19356" source="SECUNIA">19356</ref>
      <ref url="http://secunia.com/advisories/19349" source="SECUNIA">19349</ref>
      <ref url="http://secunia.com/advisories/19346" source="SECUNIA">19346</ref>
      <ref url="http://secunia.com/advisories/19345" source="SECUNIA">19345</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=c00692635" source="HP">HPSBTU02116</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c00629555" source="HP">HPSBUX02108</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060401-01-U" source="SGI">20060401-01-U</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060302-01-P" source="SGI">20060302-01-P</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.24/SCOSA-2006.24.txt" source="SCO">SCOSA-2006.24</ref>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2006-010.txt.asc" source="NETBSD">NetBSD-SA2006-010</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:13.sendmail.asc" source="FREEBSD">FreeBSD-SA-06:13</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1689" source="OVAL" sig="1">oval:org.mitre.oval:def:1689</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sendmail" name="sendmail">
        <vers num="8.13.0"/>
        <vers num="8.13.1"/>
        <vers num="8.13.2"/>
        <vers num="8.13.3"/>
        <vers num="8.13.4"/>
        <vers num="8.13.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0059" published="2006-05-19" name="CVE-2006-0059" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the ISO Transport Service over TCP (RFC 1006) implementation of LiveData ICCP Server before 5.00.035 allows remote attackers to cause a denial of service or execute arbitrary code via malformed packets.</descript>
    </desc>
    <sols>
      <sol source="nvd">This vulnerability is addressed in the following product release:
LiveData, ICCP Server, 5.00.035</sol>
    </sols>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/190617" source="CERT-VN" patch="1">VU#190617</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1830" source="VUPEN">ADV-2006-1830</ref>
      <ref url="http://www.kb.cert.org/vuls/id/JGEI-6MMS9T" source="MISC">http://www.kb.cert.org/vuls/id/JGEI-6MMS9T</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/26490" source="XF">livedata-iccp-rfc1006-bo(26490)</ref>
      <ref url="http://www.securityfocus.com/bid/18010" source="BID">18010</ref>
      <ref url="http://www.digitalbond.com/SCADA_Blog/2006/05/us-cert-livedata-iccp-vulnerability.html" source="MISC">http://www.digitalbond.com/SCADA_Blog/2006/05/us-cert-livedata-iccp-vulnerability.html</ref>
      <ref url="http://securitytracker.com/id?1016113" source="SECTRACK">1016113</ref>
      <ref url="http://secunia.com/advisories/20146" source="SECUNIA">20146</ref>
    </refs>
    <vuln_soft>
      <prod vendor="livedata" name="iccp_server">
        <vers num="5.00.045"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0063" published="2006-01-05" name="CVE-2006-0063" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in phpBB 2.0.19, when "Allowed HTML tags" is enabled, allows remote attackers to inject arbitrary web script or HTML via a permitted HTML tag with ' (single quote) characters and active attributes such as onmouseover, a variant of CVE-2005-4357.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0051" source="VUPEN">ADV-2006-0051</ref>
      <ref url="http://www.osvdb.org/22672" source="OSVDB">22672</ref>
      <ref url="http://securityreason.com/securityalert/313" source="SREASON">313</ref>
      <ref url="http://securityreason.com/securityalert/313" source="MISC" adv="1">http://securityreason.com/securityalert/313</ref>
      <ref url="http://securityreason.com/achievement_securityalert/30" source="SREASONRES" adv="1">20060105 phpBB 2.0.19 XSS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb_group" name="phpbb">
        <vers num="2.0.19"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0064" published="2006-01-03" name="CVE-2006-0064" modified="2011-08-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file include vulnerability in includes/orderSuccess.inc.php in CubeCart allows remote attackers to execute arbitrary PHP code via a URL in the glob[rootDir] parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0016" source="VUPEN" adv="1">ADV-2006-0016</ref>
      <ref url="http://milw0rm.com/exploits/1398" source="MILW0RM">1398</ref>
    </refs>
    <vuln_soft>
      <prod vendor="devellion" name="cubecart">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0065" published="2006-01-03" name="CVE-2006-0065" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in (1) functions.php, (2) functions_update.php, and (3) functions_display.php in VEGO Web Forum 1.26 and earlier allows remote attackers to execute arbitrary SQL commands via the theme_id parameter in index.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0003" source="VUPEN">ADV-2006-0003</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/420661/100/0/threaded" source="BUGTRAQ" adv="1">20060101 [eVuln] VEGO Web Forum SQL Injection Vulnerability</ref>
      <ref url="http://secunia.com/advisories/18273" source="SECUNIA" adv="1">18273</ref>
      <ref url="http://evuln.com/vulns/1/summary.html" source="MISC" adv="1">http://evuln.com/vulns/1/summary.html</ref>
      <ref url="http://www.securityfocus.com/bid/16107" source="BID">16107</ref>
      <ref url="http://www.osvdb.org/22140" source="OSVDB">22140</ref>
      <ref url="http://securityreason.com/securityalert/315" source="SREASON">315</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vego" name="vego_web_forum">
        <vers prev="1" num="1.26"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0066" published="2006-01-03" name="CVE-2006-0066" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in PHPjournaler 1.0 allows remote attackers to execute arbitrary SQL commands via the readold parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0006" source="VUPEN">ADV-2006-0006</ref>
      <ref url="http://www.securityfocus.com/bid/16111" source="BID">16111</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/420666/100/0/threaded" source="BUGTRAQ" adv="1">20060101 [eVuln] PHPjournaler SQL Injection Vulnerability</ref>
      <ref url="http://www.osvdb.org/22149" source="OSVDB">22149</ref>
      <ref url="http://secunia.com/advisories/18265" source="SECUNIA" adv="1">18265</ref>
      <ref url="http://evuln.com/vulns/9/summary.html" source="MISC" adv="1">http://evuln.com/vulns/9/summary.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpjournaler" name="phpjournaler">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0067" published="2006-01-03" name="CVE-2006-0067" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in login.php in VEGO Links Builder 2.00 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0004" source="VUPEN">ADV-2006-0004</ref>
      <ref url="http://secunia.com/advisories/18272" source="SECUNIA" adv="1">18272</ref>
      <ref url="http://evuln.com/vulns/2/summary.html" source="MISC" adv="1">http://evuln.com/vulns/2/summary.html</ref>
      <ref url="http://www.securityfocus.com/bid/16108" source="BID">16108</ref>
      <ref url="http://www.osvdb.org/22139" source="OSVDB">22139</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vego" name="vego_links_builder">
        <vers prev="1" num="2.00"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0068" published="2006-01-03" name="CVE-2006-0068" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in Primo Cart 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) q parameter to search.php and (2) email parameter to user.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0008" source="VUPEN">ADV-2006-0008</ref>
      <ref url="http://secunia.com/advisories/18264" source="SECUNIA" adv="1">18264</ref>
      <ref url="http://www.securityfocus.com/bid/16125" source="BID">16125</ref>
      <ref url="http://www.osvdb.org/22147" source="OSVDB">22147</ref>
      <ref url="http://www.osvdb.org/22146" source="OSVDB">22146</ref>
      <ref url="http://pridels0.blogspot.com/2006/01/primo-cart-sql-inj.html" source="MISC">http://pridels0.blogspot.com/2006/01/primo-cart-sql-inj.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="primo_place" name="primo_cart">
        <vers prev="1" num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0069" published="2006-01-03" name="CVE-2006-0069" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in addentry.php in Chipmunk Guestbook 1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the homepage parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/19087" source="BID">19087</ref>
      <ref url="http://www.securityfocus.com/bid/16112" source="BID">16112</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/420667/100/0/threaded" source="BUGTRAQ" adv="1">20060101 [eVuln] Chipmunk Guestbook XSS Vulnerability</ref>
      <ref url="http://secunia.com/advisories/18270" source="SECUNIA">18270</ref>
      <ref url="http://evuln.com/vulns/4/summary.html" source="MISC" adv="1">http://evuln.com/vulns/4/summary.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="chipmunk_scripts" name="chipmunk_guestbook">
        <vers prev="1" num="1.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0070" published="2006-01-03" name="CVE-2006-0070" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">** DISPUTED **  Drupal allows remote attackers to conduct cross-site scripting (XSS) attacks via an IMG tag with an unusual encoded Javascript function name, as demonstrated using variations of the alert() function.  NOTE: a followup by the vendor suggests that the issue does not exist in 4.5.6 or 4.6.4 when "Filtered HTML" is enabled, and since "Full HTML" would not filter HTML by design, perhaps this should not be included in CVE.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/420683/100/0/threaded" source="BUGTRAQ">20060103 Re: Drupal all versiyon xss cehennem.org</ref>
      <ref url="http://www.securityfocus.com/archive/1/420671/100/0/threaded" source="BUGTRAQ" adv="1">20060102 Drupal all versiyon xss cehennem.org</ref>
    </refs>
    <vuln_soft>
      <prod vendor="drupal" name="drupal">
        <vers num="4.5.6"/>
        <vers num="4.6.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0071" published="2006-01-03" name="CVE-2006-0071" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:N)" CVSS_score="6.6" CVSS_impact_subscore="9.2" CVSS_exploit_subscore="3.9" CVSS_base_score="6.6">
    <desc>
      <descript source="cve">The ebuild for pinentry before 0.7.2-r2 on Gentoo Linux sets setgid bits for pinentry programs, which allows local users to read or overwrite arbitrary files as gid 0.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16120" source="BID" patch="1">16120</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200601-01.xml" source="GENTOO" patch="1" adv="1">GLSA-200601-01</ref>
      <ref url="http://www.osvdb.org/22211" source="OSVDB">22211</ref>
      <ref url="http://secunia.com/advisories/18284" source="SECUNIA">18284</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gentoo" name="app-crypt_pinentry">
        <vers num="0.7.2" edition="r1"/>
      </prod>
      <prod vendor="gentoo" name="linux">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0072" published="2006-01-03" name="CVE-2006-0072" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in termsh on SCO OpenServer 5.0.7 allows remote attackers to execute arbitrary code via a long -o command line argument.  NOTE: this is probably a different vulnerability than CVE-2005-0351 since it involves a distinct attack vector.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16122" source="BID">16122</ref>
      <ref url="http://www.securityfocus.com/archive/1/420677" source="BUGTRAQ">20060102 SCO Openserver 5.0.x exploit</ref>
      <ref url="http://downloads.securityfocus.com/vulnerabilities/exploits/Openserver_bof.c" source="MISC">http://downloads.securityfocus.com/vulnerabilities/exploits/Openserver_bof.c</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="openserver">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4"/>
        <vers num="5.0.5"/>
        <vers num="5.0.6"/>
        <vers num="5.0.6a"/>
        <vers num="5.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0073" published="2006-01-03" name="CVE-2006-0073" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in DiscusWare Discus Freeware 3.10.5 and Professional 3.10.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in a URL, which is not properly sanitized from the resulting error message.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16119" source="BID">16119</ref>
      <ref url="http://www.osvdb.org/22153" source="OSVDB">22153</ref>
      <ref url="http://secunia.com/advisories/18283" source="SECUNIA" adv="1">18283</ref>
    </refs>
    <vuln_soft>
      <prod vendor="discusware" name="discus_freeware">
        <vers num="3.10.5"/>
      </prod>
      <prod vendor="discusware" name="discus_professional">
        <vers num="3.10.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0074" published="2006-01-03" name="CVE-2006-0074" modified="2011-08-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in profile.php in PHPenpals allows remote attackers to execute arbitrary SQL commands via the personalID parameter.  NOTE: it was later reported that 1.1 and earlier are affected.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0005" source="VUPEN" adv="1">ADV-2006-0005</ref>
      <ref url="http://www.securityfocus.com/bid/16109" source="BID">16109</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/420690/100/0/threaded" source="BUGTRAQ">20060101 [eVuln] PHPenpals SQL Injection Vulnerabilit</ref>
      <ref url="http://www.osvdb.org/22150" source="OSVDB">22150</ref>
      <ref url="http://www.milw0rm.com/exploits/8706" source="MILW0RM">8706</ref>
      <ref url="http://secunia.com/advisories/18269" source="SECUNIA" adv="1">18269</ref>
      <ref url="http://evuln.com/vulns/5/summary.html" source="MISC">http://evuln.com/vulns/5/summary.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jevontech" name="phpenpals">
        <vers prev="1" num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0075" published="2006-01-03" name="CVE-2006-0075" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Direct static code injection vulnerability in phpBook 1.3.2 and earlier allows remote attackers to execute arbitrary PHP code via the e-mail field (mail variable) in a new message, which is written to a PHP file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16106" source="BID" patch="1" adv="1">16106</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/420698/100/0/threaded" source="BUGTRAQ" patch="1">20060101 [eVuln] phpBook PHP Code Execution</ref>
      <ref url="http://evuln.com/vulns/6/summary.html" source="MISC" patch="1">http://evuln.com/vulns/6/summary.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0002" source="VUPEN">ADV-2006-0002</ref>
      <ref url="http://secunia.com/advisories/18268" source="SECUNIA" adv="1">18268</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="phpbook">
        <vers num="1.0"/>
        <vers num="1.1"/>
        <vers num="1.2"/>
        <vers num="1.3"/>
        <vers prev="1" num="1.3.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0076" published="2006-01-03" name="CVE-2006-0076" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file include vulnerability in forum.php in oaBoard 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the inc parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16105" source="BID">16105</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/435859/100/0/threaded" source="BUGTRAQ">20060531 Re: OaBoard 1.0 Remote File inclusion</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/435371/100/0/threaded" source="BUGTRAQ">20060530 OaBoard 1.0 Remote File inclusion</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/420676/100/0/threaded" source="BUGTRAQ" adv="1">20060101 [eVuln] oaBoard PHP Code Execution</ref>
      <ref url="http://securitytracker.com/id?1016211" source="SECTRACK">1016211</ref>
      <ref url="http://evuln.com/vulns/3/summary.html" source="MISC">http://evuln.com/vulns/3/summary.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oaboard" name="oaboard">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0077" published="2006-01-03" name="CVE-2006-0077" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Off-by-one error in the getfattr function in File::ExtAttr before 0.03 allows attackers to trigger a buffer overflow via unspecified attack vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16118" source="BID" patch="1">16118</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=382199&amp;group_id=153116" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=382199&amp;group_id=153116</ref>
      <ref url="http://secunia.com/advisories/18253" source="SECUNIA" patch="1" adv="1">18253</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0013" source="VUPEN">ADV-2006-0013</ref>
      <ref url="http://www.osvdb.org/22160" source="OSVDB">22160</ref>
    </refs>
    <vuln_soft>
      <prod vendor="richard_dawe" name="file_extattr">
        <vers num="0.1"/>
        <vers num="0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0078" published="2006-01-04" name="CVE-2006-0078" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in B-net Software 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) name and (2) shout variables to (a) shout.php, or the (3) title and (4) message variables to (b) guestbook.php.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0018" source="VUPEN">ADV-2006-0018</ref>
      <ref url="http://www.securityfocus.com/bid/16114" source="BID">16114</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/420673/100/0/threaded" source="BUGTRAQ" adv="1">20060102 [eVuln] B-net Software Multiple XSS Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/18271" source="SECUNIA" adv="1">18271</ref>
      <ref url="http://evuln.com/vulns/10/summary.html" source="MISC" adv="1">http://evuln.com/vulns/10/summary.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/444320/100/0/threaded" source="BUGTRAQ">20060825 Re: [eVuln] B-net Software Multiple XSS Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/22191" source="OSVDB">22191</ref>
      <ref url="http://www.osvdb.org/22190" source="OSVDB">22190</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=442067&amp;group_id=117067" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=442067&amp;group_id=117067</ref>
      <ref url="http://securityreason.com/securityalert/316" source="SREASON">316</ref>
    </refs>
    <vuln_soft>
      <prod vendor="haddad_said" name="b-net_software">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0079" published="2006-01-04" name="CVE-2006-0079" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in auth.php in ScozNet ScozBook BETA 1.1 allows remote attackers to execute arbitrary SQL commands via the username field (adminname variable).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0027" source="VUPEN">ADV-2006-0027</ref>
      <ref url="http://www.securityfocus.com/bid/16115" source="BID">16115</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/420675/100/0/threaded" source="BUGTRAQ" adv="1">20060102 [eVuln] ScozBook "adminname" Authentication Bypass</ref>
      <ref url="http://evuln.com/vulns/11/summary.html" source="MISC">http://evuln.com/vulns/11/summary.html</ref>
      <ref url="http://www.osvdb.org/22221" source="OSVDB">22221</ref>
      <ref url="http://securityreason.com/securityalert/318" source="SREASON">318</ref>
      <ref url="http://secunia.com/advisories/8476" source="SECUNIA">8476</ref>
    </refs>
    <vuln_soft>
      <prod vendor="scoznet" name="scozbook">
        <vers num="1.1_beta"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0080" published="2006-01-04" name="CVE-2006-0080" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in vBulletin 3.5.2, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the title of an event, which is not properly filtered by (1) calendar.php and (2) reminder.php.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0033" source="VUPEN">ADV-2006-0033</ref>
      <ref url="http://www.securityfocus.com/bid/16116" source="BID">16116</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421310/100/0/threaded" source="BUGTRAQ">20060108 Html_Injection in vBulletin 3.5.2</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/420663/100/0/threaded" source="BUGTRAQ" adv="1">20060101 [KAPDA::#19] - Html Injection in vBulletin 3.5.2</ref>
      <ref url="http://www.osvdb.org/22220" source="OSVDB">22220</ref>
      <ref url="http://www.osvdb.org/22210" source="OSVDB">22210</ref>
      <ref url="http://secunia.com/advisories/18299" source="SECUNIA">18299</ref>
      <ref url="http://kapda.ir/advisory-177.html" source="MISC" adv="1">http://kapda.ir/advisory-177.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jelsoft" name="vbulletin">
        <vers num="3.5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0081" published="2006-01-04" name="CVE-2006-0081" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">ialmnt5.sys in the ialmrnt5 display driver in Intel Graphics Accelerator Driver 6.14.10.4308 allows attackers to cause a denial of service (crash or screen resolution change) via a long text field, as demonstrated using a long window title.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0017" source="VUPEN" adv="1">ADV-2006-0017</ref>
      <ref url="http://www.securityfocus.com/bid/16127" source="BID">16127</ref>
      <ref url="http://www.osvdb.org/22196" source="OSVDB">22196</ref>
      <ref url="http://secunia.com/advisories/18286" source="SECUNIA" adv="1">18286</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0029.html" source="FULLDISC">20060103 Re: Buffer Overflow vulnerability in Windows Display Manager [Suspected]</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0029.html" source="FULLDISC">20060103 Re: Buffer Overflow vulnerability in Windows Display Manager [Suspected]</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0003.html" source="FULLDISC">20060102 Buffer Overflow vulnerability in Windows Display Manager [Suspected]</ref>
    </refs>
    <vuln_soft>
      <prod vendor="intel" name="graphics_accelerator_driver">
        <vers num="6.14.10.4308"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0082" published="2006-01-04" name="CVE-2006-0082" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Format string vulnerability in the SetImageInfo function in image.c for ImageMagick 6.2.3 and other versions, and GraphicsMagick, allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a numeric format string specifier such as %d in the file name, a variant of CVE-2005-0397, and as demonstrated using the convert program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/12717" source="BID" patch="1">12717</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200602-13.xml" source="GENTOO" patch="1" adv="1">GLSA-200602-13.xml</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200602-06.xml" source="GENTOO" patch="1" adv="1">GLSA-200602-06</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.341682" source="SLACKWARE" patch="1">SSA:2006-045-03</ref>
      <ref url="http://secunia.com/advisories/19183" source="SECUNIA" patch="1" adv="1">19183</ref>
      <ref url="http://secunia.com/advisories/19030" source="SECUNIA" patch="1" adv="1">19030</ref>
      <ref url="http://secunia.com/advisories/18851" source="SECUNIA" patch="1" adv="1">18851</ref>
      <ref url="http://secunia.com/advisories/18607" source="SECUNIA" patch="1" adv="1">18607</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060301-01.U.asc" source="SGI" patch="1">20060301-01-U</ref>
      <ref url="https://issues.rpath.com/browse/RPL-389" source="CONFIRM">https://issues.rpath.com/browse/RPL-389</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0412" source="VUPEN" adv="1">ADV-2008-0412</ref>
      <ref url="http://www.ubuntu.com/usn/usn-246-1" source="UBUNTU">USN-246-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/452718/100/100/threaded" source="BUGTRAQ">20061127 rPSA-2006-0218-1 ImageMagick</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_06_sr.html" source="SUSE">SUSE-SR:2006:006</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:024" source="MANDRIVA">MDKSA-2006:024</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1213" source="DEBIAN">DSA-1213</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-231321-1" source="SUNALERT">231321</ref>
      <ref url="http://securitytracker.com/id?1015623" source="SECTRACK">1015623</ref>
      <ref url="http://securityreason.com/securityalert/500" source="SREASON">500</ref>
      <ref url="http://secunia.com/advisories/28800" source="SECUNIA" adv="1">28800</ref>
      <ref url="http://secunia.com/advisories/23090" source="SECUNIA" adv="1">23090</ref>
      <ref url="http://secunia.com/advisories/22998" source="SECUNIA" adv="1">22998</ref>
      <ref url="http://secunia.com/advisories/19408" source="SECUNIA" adv="1">19408</ref>
      <ref url="http://secunia.com/advisories/18871" source="SECUNIA" adv="1">18871</ref>
      <ref url="http://secunia.com/advisories/18261" source="SECUNIA" adv="1">18261</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2006-0178.html" source="REDHAT">RHSA-2006:0178</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10717" source="OVAL">oval:org.mitre.oval:def:10717</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=345876" source="CONFIRM" adv="1">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=345876</ref>
    </refs>
    <vuln_soft>
      <prod vendor="imagemagick" name="imagemagick">
        <vers num="6.2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0083" published="2006-01-09" name="CVE-2006-0083" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Format string vulnerability in the logging code of SMS Server Tools (smstools) 1.14.8 and earlier allows local users to execute arbitrary code via unspecified attack vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18357" source="SECUNIA" patch="1" adv="1">18357</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24034" source="XF">smstools-logging-format-string(24034)</ref>
      <ref url="http://www.securityfocus.com/bid/16188" source="BID">16188</ref>
      <ref url="http://www.osvdb.org/22287" source="OSVDB">22287</ref>
      <ref url="http://www.debian.org/security/2005/dsa-930" source="DEBIAN">DSA-930</ref>
      <ref url="http://secunia.com/advisories/18343" source="SECUNIA" adv="1">18343</ref>
    </refs>
    <vuln_soft>
      <prod vendor="stefan_frings" name="sms_server_tools">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0084" published="2006-01-05" name="CVE-2006-0084" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability in index.php in raSMP 2.0.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the $_SERVER[HTTP_USER_AGENT] variable (User-Agent header).</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0030" source="VUPEN">ADV-2006-0030</ref>
      <ref url="http://www.securityfocus.com/bid/16138" source="BID">16138</ref>
      <ref url="http://www.osvdb.org/22198" source="OSVDB">22198</ref>
      <ref url="http://secunia.com/advisories/18292" source="SECUNIA" adv="1">18292</ref>
      <ref url="http://evuln.com/vulns/13/summary.html" source="MISC" adv="1">http://evuln.com/vulns/13/summary.html</ref>
      <ref url="http://securitytracker.com/id?1015432" source="SECTRACK">1015432</ref>
      <ref url="http://attrition.org/pipermail/vim/2006-January/000486.html" source="VIM">20060116 vendor ack/fix: 22198: raSMP index.php User-Agent Field XSS (fwd)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rasmp" name="rasmp">
        <vers num="2.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0085" published="2006-01-05" name="CVE-2006-0085" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in Nkads 1.0 alfa 3 allows remote attackers to execute arbitrary SQL commands via the (1) usuario_nkads_admin or (2) password_nkads_admin parameters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0040" source="VUPEN">ADV-2006-0040</ref>
      <ref url="http://www.soulblack.com.ar/repo/papers/advisory/nkads_advisory.txt" source="MISC" adv="1">http://www.soulblack.com.ar/repo/papers/advisory/nkads_advisory.txt</ref>
      <ref url="http://secunia.com/advisories/18302" source="SECUNIA" adv="1">18302</ref>
      <ref url="http://www.osvdb.org/22206" source="OSVDB">22206</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nkads" name="nkads">
        <vers num="1.0alfa2"/>
        <vers num="1.0alfa3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0086" published="2006-01-05" name="CVE-2006-0086" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability in index.php in Next Generation Image Gallery 0.0.1 Lite Edition allows remote attackers to inject arbitrary web script or HTML via the page parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0037" source="VUPEN">ADV-2006-0037</ref>
      <ref url="http://secunia.com/advisories/18309" source="SECUNIA" adv="1">18309</ref>
      <ref url="http://www.osvdb.org/22202" source="OSVDB">22202</ref>
      <ref url="http://osvdb.org/ref/22/22202-nextgen.txt" source="MISC">http://osvdb.org/ref/22/22202-nextgen.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="next_generation_image_gallery" name="next_generation_image_gallery">
        <vers num="0.0.1_lite"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0087" published="2006-01-05" name="CVE-2006-0087" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in (1) pages.php and (2) detail.php in Lizard Cart CMS 1.04 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0029" source="VUPEN">ADV-2006-0029</ref>
      <ref url="http://www.securityfocus.com/bid/16140" source="BID">16140</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/420772/100/0/threaded" source="BUGTRAQ" adv="1">20060104 [eVuln] Lizard Cart CMS SQL Injection Vulnerability</ref>
      <ref url="http://secunia.com/advisories/18297" source="SECUNIA" adv="1">18297</ref>
      <ref url="http://www.osvdb.org/22200" source="OSVDB">22200</ref>
      <ref url="http://www.osvdb.org/22199" source="OSVDB">22199</ref>
      <ref url="http://www.evuln.com/vulns/12/summary.html" source="MISC">http://www.evuln.com/vulns/12/summary.html</ref>
      <ref url="http://securitytracker.com/id?1015435" source="SECTRACK">1015435</ref>
      <ref url="http://securityreason.com/securityalert/314" source="SREASON">314</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lizard_cart" name="lizard_cart_cms">
        <vers num="1.0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0088" published="2006-01-05" name="CVE-2006-0088" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in intouch.lib.php in inTouch 0.5.1 Alpha allows remote attackers to execute arbitrary SQL commands via the user parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0026" source="VUPEN">ADV-2006-0026</ref>
      <ref url="http://www.securityfocus.com/bid/16110" source="BID">16110</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/420672/100/0/threaded" source="BUGTRAQ" adv="1">20060101 [eVuln] inTouch Authentication Bypass</ref>
      <ref url="http://evuln.com/vulns/8/summary.html" source="MISC" adv="1">http://evuln.com/vulns/8/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/23954" source="XF">intouch-intouch-sql-injection(23954)</ref>
      <ref url="http://www.osvdb.org/22382" source="OSVDB">22382</ref>
    </refs>
    <vuln_soft>
      <prod vendor="intouch" name="intouch">
        <vers num="0.5.1_alpha"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0089" published="2006-01-05" name="CVE-2006-0089" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in ESRI ArcPad 7.0.0.156 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a .amp file with a COORDSYS tag with a long string attribute.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0032" source="VUPEN">ADV-2006-0032</ref>
      <ref url="http://www.securityfocus.com/bid/16136" source="BID">16136</ref>
      <ref url="http://users.pandora.be/bratax/advisories/b007.html" source="MISC" adv="1">http://users.pandora.be/bratax/advisories/b007.html</ref>
      <ref url="http://secunia.com/advisories/18294" source="SECUNIA" adv="1">18294</ref>
      <ref url="http://www.osvdb.org/22208" source="OSVDB">22208</ref>
    </refs>
    <vuln_soft>
      <prod vendor="esri" name="arcpad">
        <vers prev="1" num="7.0.0.156"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0090" published="2006-01-05" name="CVE-2006-0090" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in index.php in IDV Directory Viewer before 2005.1 allows remote attackers to view arbitrary directory contents via a .. (dot dot) in the dir parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=382593&amp;group_id=152499" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=382593&amp;group_id=152499</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0031" source="VUPEN">ADV-2006-0031</ref>
      <ref url="http://secunia.com/advisories/18298" source="SECUNIA" adv="1">18298</ref>
      <ref url="http://www.securityfocus.com/bid/16137" source="BID">16137</ref>
    </refs>
    <vuln_soft>
      <prod vendor="idv_directory_viewer" name="idv_directory_viewer">
        <vers num="2005.1_b1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0091" published="2006-01-05" name="CVE-2006-0091" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in webmail in Open-Xchange 0.8.1-6 and earlier, with "Inline HTML" enabled, allows remote attackers to inject arbitrary web script or HTML via e-mail attachments, which are rendered inline.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0034" source="VUPEN">ADV-2006-0034</ref>
      <ref url="http://secunia.com/advisories/18285" source="SECUNIA" adv="1">18285</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=113629092325679&amp;w=2" source="FULLDISC" adv="1">20060103 Open Xchange XSS</ref>
      <ref url="http://securitytracker.com/id?1015431" source="SECTRACK">1015431</ref>
    </refs>
    <vuln_soft>
      <prod vendor="open-xchange" name="open-xchange">
        <vers prev="1" num="0.8.1.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2006-0092" reject="1" published="2006-01-05" name="CVE-2006-0092" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2006-0992, CVE-2006-0158.  Reason: this candidate was intended for one issue, but a typo caused it to be associated with a Novell/Groupwise issue.  In addition, this issue was a duplicate of a SiteSuite issue that was also assigned CVE-2006-0158.  Notes: All CVE users should consult CVE-2006-0992 and CVE-2006-0158 to determine which ID is appropriate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <vuln_types>
      <input/>
    </vuln_types>
    <refs/>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0093" published="2006-01-05" name="CVE-2006-0093" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in @Card ME PHP allows remote attackers to inject arbitrary web script or HTML via the cat parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0039" source="VUPEN">ADV-2006-0039</ref>
      <ref url="http://www.osvdb.org/22203" source="OSVDB">22203</ref>
      <ref url="http://secunia.com/advisories/18306" source="SECUNIA" adv="1">18306</ref>
      <ref url="http://osvdb.org/ref/22/22203-ecardmax.txt" source="MISC">http://osvdb.org/ref/22/22203-ecardmax.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ecardmax.com" name="atcard_me_php">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0094" published="2006-01-05" name="CVE-2006-0094" modified="2011-08-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file include vulnerability in forum.php in oaBoard 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the inc_stat parameter, a different vulnerability than CVE-2006-0076. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0028" source="VUPEN" adv="1">ADV-2006-0028</ref>
      <ref url="http://secunia.com/advisories/17373" source="SECUNIA" adv="1">17373</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oaboard" name="oaboard">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0095" published="2006-01-06" name="CVE-2006-0095" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">dm-crypt in Linux kernel 2.6.15 and earlier does not clear a structure before it is freed, which leads to a memory disclosure that could allow local users to obtain sensitive information about a cryptographic key.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://marc.theaimsgroup.com/?l=linux-kernel&amp;m=113640535312572&amp;w=2" source="MLIST" patch="1" adv="1">[linux-kernel] 20060104 [Patch 2.6] dm-crypt: zero key before freeing it</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0235" source="VUPEN">ADV-2006-0235</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11192" source="OVAL">oval:org.mitre.oval:def:11192</ref>
      <ref url="http://marc.theaimsgroup.com/?l=linux-kernel&amp;m=113641114812886&amp;w=2" source="MLIST">[linux-kernel] 20060104 [Patch 2.6] dm-crypt: Zero key material before free to avoid information leak</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24189" source="XF">kernel-dmcrypt-information-disclosure(24189)</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-244-1" source="UBUNTU">USN-244-1</ref>
      <ref url="http://www.trustix.org/errata/2006/0004" source="TRUSTIX">2006-0004</ref>
      <ref url="http://www.securityfocus.com/bid/16301" source="BID">16301</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427981/100/0/threaded" source="FEDORA">FLSA:157459-4</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0132.html" source="REDHAT">RHSA-2006:0132</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-February/msg00037.html" source="FEDORA">FEDORA-2006-102</ref>
      <ref url="http://www.osvdb.org/22418" source="OSVDB">22418</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006-05-31.html" source="SUSE">SUSE-SA:2006:028</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:040" source="MANDRIVA">MDKSA-2006:040</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1017" source="DEBIAN">DSA-1017</ref>
      <ref url="http://securitytracker.com/id?1015740" source="SECTRACK">1015740</ref>
      <ref url="http://securityreason.com/securityalert/388" source="SREASON">388</ref>
      <ref url="http://secunia.com/advisories/20398" source="SECUNIA">20398</ref>
      <ref url="http://secunia.com/advisories/19374" source="SECUNIA">19374</ref>
      <ref url="http://secunia.com/advisories/19160" source="SECUNIA">19160</ref>
      <ref url="http://secunia.com/advisories/18774" source="SECUNIA">18774</ref>
      <ref url="http://secunia.com/advisories/18527" source="SECUNIA">18527</ref>
      <ref url="http://secunia.com/advisories/18487" source="SECUNIA">18487</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0"/>
        <vers num="2.6.1"/>
        <vers num="2.6.10"/>
        <vers num="2.6.11"/>
        <vers num="2.6.11.1"/>
        <vers num="2.6.11.10"/>
        <vers num="2.6.11.11"/>
        <vers num="2.6.11.12"/>
        <vers num="2.6.11.2"/>
        <vers num="2.6.11.3"/>
        <vers num="2.6.11.4"/>
        <vers num="2.6.11.5"/>
        <vers num="2.6.11.6"/>
        <vers num="2.6.11.7"/>
        <vers num="2.6.11.8"/>
        <vers num="2.6.11.9"/>
        <vers num="2.6.12"/>
        <vers num="2.6.12.1"/>
        <vers num="2.6.12.2"/>
        <vers num="2.6.12.3"/>
        <vers num="2.6.12.4"/>
        <vers num="2.6.13"/>
        <vers num="2.6.14" edition="rc1"/>
        <vers num="2.6.14" edition="rc2"/>
        <vers num="2.6.14" edition="rc3"/>
        <vers num="2.6.14" edition="rc4"/>
        <vers num="2.6.14.1"/>
        <vers num="2.6.14.2"/>
        <vers num="2.6.14.3"/>
        <vers num="2.6.14.4"/>
        <vers num="2.6.15" edition="rc1"/>
        <vers num="2.6.15" edition="rc3"/>
        <vers num="2.6.15" edition="rc4"/>
        <vers num="2.6.15" edition="rc5"/>
        <vers num="2.6.15" edition="rc6"/>
        <vers num="2.6.15" edition="rc7"/>
        <vers num="2.6.2"/>
        <vers num="2.6.3"/>
        <vers num="2.6.4"/>
        <vers num="2.6.5"/>
        <vers num="2.6.6"/>
        <vers num="2.6.7"/>
        <vers num="2.6.8"/>
        <vers num="2.6.8.1"/>
        <vers num="2.6.9" edition="2.6.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0096" published="2006-01-06" name="CVE-2006-0096" modified="2008-11-20" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">wan/sdla.c in Linux kernel 2.6.x before 2.6.11 and 2.4.x before 2.4.29 does not require the CAP_SYS_RAWIO privilege for an SDLA firmware upgrade, with unknown impact and local attack vectors.  NOTE: further investigation suggests that this issue requires root privileges to exploit, since it is protected by CAP_NET_ADMIN; thus it might not be a vulnerability, although capabilities provide finer distinctions between privilege levels.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:044" source="MANDRIVA">MDKSA-2006:044</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-244-1" source="UBUNTU">USN-244-1</ref>
      <ref url="http://www.securityfocus.com/bid/16304" source="BID">16304</ref>
      <ref url="http://www.kernel.org/git/?p=linux/kernel/git/tglx/history.git;a=commitdiff;h=0f1d4813a4a65296e1131f320a60741732bc068f" source="CONFIRM">http://www.kernel.org/git/?p=linux/kernel/git/tglx/history.git;a=commitdiff;h=0f1d4813a4a65296e1131f320a60741732bc068f</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1017" source="DEBIAN">DSA-1017</ref>
      <ref url="http://secunia.com/advisories/19374" source="SECUNIA" adv="1">19374</ref>
      <ref url="http://secunia.com/advisories/18977" source="SECUNIA" adv="1">18977</ref>
      <ref url="http://secunia.com/advisories/18527" source="SECUNIA" adv="1">18527</ref>
      <ref url="http://linux.bkbits.net:8080/linux-2.4/cset@1.1448.91.23?nav=index.html%7Csrc/%7Csrc/drivers%7Csrc/drivers/net%7Csrc/drivers/net/wan%7Crelated/drivers/net/wan/sdla.c" source="CONFIRM">http://linux.bkbits.net:8080/linux-2.4/cset@1.1448.91.23?nav=index.html|src/|src/drivers|src/drivers/net|src/drivers/net/wan|related/drivers/net/wan/sdla.c</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.4.0" edition="test1"/>
        <vers num="2.4.0" edition="test10"/>
        <vers num="2.4.0" edition="test11"/>
        <vers num="2.4.0" edition="test12"/>
        <vers num="2.4.0" edition="test2"/>
        <vers num="2.4.0" edition="test3"/>
        <vers num="2.4.0" edition="test4"/>
        <vers num="2.4.0" edition="test5"/>
        <vers num="2.4.0" edition="test6"/>
        <vers num="2.4.0" edition="test7"/>
        <vers num="2.4.0" edition="test8"/>
        <vers num="2.4.0" edition="test9"/>
        <vers num="2.4.1"/>
        <vers num="2.4.10"/>
        <vers num="2.4.11"/>
        <vers num="2.4.12"/>
        <vers num="2.4.13"/>
        <vers num="2.4.14"/>
        <vers num="2.4.15"/>
        <vers num="2.4.16"/>
        <vers num="2.4.17"/>
        <vers num="2.4.18" edition=""/>
        <vers num="2.4.18" edition=":x86"/>
        <vers num="2.4.18" edition="pre1"/>
        <vers num="2.4.18" edition="pre2"/>
        <vers num="2.4.18" edition="pre3"/>
        <vers num="2.4.18" edition="pre4"/>
        <vers num="2.4.18" edition="pre5"/>
        <vers num="2.4.18" edition="pre6"/>
        <vers num="2.4.18" edition="pre7"/>
        <vers num="2.4.18" edition="pre8"/>
        <vers num="2.4.19" edition="pre1"/>
        <vers num="2.4.19" edition="pre2"/>
        <vers num="2.4.19" edition="pre3"/>
        <vers num="2.4.19" edition="pre4"/>
        <vers num="2.4.19" edition="pre5"/>
        <vers num="2.4.19" edition="pre6"/>
        <vers num="2.4.2"/>
        <vers num="2.4.20"/>
        <vers num="2.4.21" edition="pre1"/>
        <vers num="2.4.21" edition="pre4"/>
        <vers num="2.4.21" edition="pre7"/>
        <vers num="2.4.22"/>
        <vers num="2.4.23" edition="pre9"/>
        <vers num="2.4.23_ow2"/>
        <vers num="2.4.24"/>
        <vers num="2.4.24_ow1"/>
        <vers num="2.4.25"/>
        <vers num="2.4.26"/>
        <vers num="2.4.27" edition="pre1"/>
        <vers num="2.4.27" edition="pre2"/>
        <vers num="2.4.27" edition="pre3"/>
        <vers num="2.4.27" edition="pre4"/>
        <vers num="2.4.27" edition="pre5"/>
        <vers num="2.4.28"/>
        <vers num="2.4.3"/>
        <vers num="2.4.4"/>
        <vers num="2.4.5"/>
        <vers num="2.4.6"/>
        <vers num="2.4.7"/>
        <vers num="2.4.8"/>
        <vers num="2.4.9"/>
        <vers num="2.6.0"/>
        <vers num="2.6.1"/>
        <vers num="2.6.10"/>
        <vers num="2.6.11"/>
        <vers num="2.6.11.1"/>
        <vers num="2.6.11.10"/>
        <vers num="2.6.11.11"/>
        <vers num="2.6.11.12"/>
        <vers num="2.6.11.2"/>
        <vers num="2.6.11.3"/>
        <vers num="2.6.11.4"/>
        <vers num="2.6.11.5"/>
        <vers num="2.6.11.6"/>
        <vers num="2.6.11.7"/>
        <vers num="2.6.11.8"/>
        <vers num="2.6.11.9"/>
        <vers num="2.6.12"/>
        <vers num="2.6.12.1"/>
        <vers num="2.6.12.2"/>
        <vers num="2.6.12.3"/>
        <vers num="2.6.12.4"/>
        <vers num="2.6.13"/>
        <vers num="2.6.14" edition="rc1"/>
        <vers num="2.6.14" edition="rc2"/>
        <vers num="2.6.14" edition="rc3"/>
        <vers num="2.6.14" edition="rc4"/>
        <vers num="2.6.14.1"/>
        <vers num="2.6.14.2"/>
        <vers num="2.6.14.3"/>
        <vers num="2.6.14.4"/>
        <vers num="2.6.15" edition="rc1"/>
        <vers num="2.6.15" edition="rc3"/>
        <vers num="2.6.15" edition="rc4"/>
        <vers num="2.6.15" edition="rc5"/>
        <vers num="2.6.15" edition="rc6"/>
        <vers num="2.6.15" edition="rc7"/>
        <vers num="2.6.2"/>
        <vers num="2.6.3"/>
        <vers num="2.6.4"/>
        <vers num="2.6.5"/>
        <vers num="2.6.6"/>
        <vers num="2.6.7"/>
        <vers num="2.6.8"/>
        <vers num="2.6.8.1"/>
        <vers num="2.6.9" edition="2.6.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0097" published="2006-01-06" name="CVE-2006-0097" modified="2011-08-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the create_named_pipe function in libmysql.c in PHP 4.3.10 and 4.4.x before 4.4.3 for Windows allows attackers to execute arbitrary code via a long (1) arg_host or (2) arg_unix_socket argument, as demonstrated by a long named pipe variable in the host argument to the mysql_connect function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0046" source="VUPEN" adv="1">ADV-2006-0046</ref>
      <ref url="http://www.securityfocus.com/bid/16145" source="BID">16145</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/420986/100/0/threaded" source="BUGTRAQ">20060105 Windows PHP 4.x </ref>
      <ref url="http://www.php.net/ChangeLog-4.php#4.4.3" source="CONFIRM">http://www.php.net/ChangeLog-4.php#4.4.3</ref>
      <ref url="http://www.osvdb.org/22232" source="OSVDB">22232</ref>
      <ref url="http://secunia.com/advisories/18275" source="SECUNIA" adv="1">18275</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041013.html" source="FULLDISC" adv="1">20060105 Windows PHP 4.x </ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0274.html" source="FULLDISC">20060108 RE: Windows PHP 4.x </ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="4.3.10"/>
        <vers num="4.4.0"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0098" published="2006-01-06" name="CVE-2006-0098" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The dupfdopen function in sys/kern/kern_descrip.c in OpenBSD 3.7 and 3.8 allows local users to re-open arbitrary files by using setuid programs to access file descriptors using /dev/fd/.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16144" source="BID" patch="1">16144</ref>
      <ref url="http://www.openbsd.org/errata37.html#fd" source="OPENBSD" patch="1">[3.7] 20060105 008: SECURITY FIX: January 5, 2006</ref>
      <ref url="http://secunia.com/advisories/18296" source="SECUNIA" patch="1" adv="1">18296</ref>
      <ref url="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.7/common/008_fd.patch" source="MISC" patch="1">ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.7/common/008_fd.patch</ref>
      <ref url="http://www.osvdb.org/22231" source="OSVDB">22231</ref>
      <ref url="http://securitytracker.com/id?1015437" source="SECTRACK">1015437</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openbsd">
        <vers num="3.7"/>
        <vers num="3.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0099" published="2006-01-06" name="CVE-2006-0099" modified="2008-09-10" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file include vulnerability in (1) include/templates/categories/default.php and (2) certain other include/templates/categories/ PHP scripts in Valdersoft Shopping Cart 3.0 allows remote attackers to execute arbitrary code via a URL in the catalogDocumentRoot parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16126" source="BID">16126</ref>
      <ref url="http://downloads.securityfocus.com/vulnerabilities/exploits/cijfer-vscxpl.pl" source="MISC">http://downloads.securityfocus.com/vulnerabilities/exploits/cijfer-vscxpl.pl</ref>
      <ref url="http://milw0rm.com/exploits/1401" source="MILW0RM">1401</ref>
    </refs>
    <vuln_soft>
      <prod vendor="valdersoft" name="valdersoft_shopping_cart">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0100" published="2006-01-06" name="CVE-2006-0100" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in NicoFTP 3.0.1.19 and earlier might allow local users to execute arbitrary code via a long string in the "Name of site" field of an FTP account.  NOTE: because this program executes with the privileges of the invoking user, and because remote programs do not normally have the ability to create or modify FTP accounts in this program, there may not be a typical attack vector for the issue that crosses privilege boundaries.  Therefore this may not be a vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/420670/100/0/threaded" source="BUGTRAQ">20060102 NicoFTP Stack Overflow</ref>
      <ref url="http://securityreason.com/securityalert/317" source="SREASON">317</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nicosw" name="nicoftp">
        <vers prev="1" num="3.0.1.19"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0101" published="2006-01-06" name="CVE-2006-0101" modified="2011-09-13" discovered="2006-01-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in sBLOG 0.7.1 Beta 20051202 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) p and (2) keyword parameters in (a) index.php and (b) search.php.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/23979" source="XF">sblog-multiple-scripts-xss(23979)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0041" source="VUPEN" adv="1">ADV-2006-0041</ref>
      <ref url="http://www.osvdb.org/22374" source="OSVDB">22374</ref>
      <ref url="http://www.osvdb.org/22373" source="OSVDB">22373</ref>
      <ref url="http://osvdb.org/ref/22/22373-sblog.txt" source="MISC">http://osvdb.org/ref/22/22373-sblog.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sblog" name="sblog">
        <vers prev="1" num="0.7.1_build2005-12-02_beta"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0102" published="2006-01-06" name="CVE-2006-0102" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in TinyPHPForum (TPF) 3.6 and earlier allows remote attackers to inject arbitrary web script via a javascript: scheme in an "[a]" bbcode tag, possibly the txt parameter to action.php.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0054" source="VUPEN">ADV-2006-0054</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/420933/100/0/threaded" source="BUGTRAQ">20060105 [eVuln] TinyPHPForum Multiple Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/22256" source="OSVDB">22256</ref>
      <ref url="http://securitytracker.com/id?1015436" source="SECTRACK">1015436</ref>
      <ref url="http://secunia.com/advisories/18293" source="SECUNIA" adv="1">18293</ref>
      <ref url="http://evuln.com/vulns/14/summary.html" source="MISC" adv="1">http://evuln.com/vulns/14/summary.html</ref>
      <ref url="http://securityreason.com/securityalert/320" source="SREASON">320</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ralph_capper" name="tinyphpforum">
        <vers num="3.46"/>
        <vers num="3.47"/>
        <vers num="3.48"/>
        <vers num="3.49"/>
        <vers num="3.499"/>
        <vers num="3.5"/>
        <vers num="3.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0103" published="2006-01-06" name="CVE-2006-0103" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">TinyPHPForum 3.6 and earlier stores the (1) users/[USERNAME].hash and (2) users/[USERNAME].email files under the web root with insufficient access control, which allows remote attackers to list all registered users and possibly obtain other sensitive information.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24016" source="XF">tinyphpforum-users-information-disclosure(24016)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0054" source="VUPEN" adv="1">ADV-2006-0054</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431133/100/0/threaded" source="BUGTRAQ">20060417 Tiny PHP forum - vulns</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/420933/100/0/threaded" source="BUGTRAQ" adv="1">20060105 [eVuln] TinyPHPForum Multiple Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/22257" source="OSVDB">22257</ref>
      <ref url="http://securitytracker.com/id?1015436" source="SECTRACK">1015436</ref>
      <ref url="http://securityreason.com/securityalert/320" source="SREASON">320</ref>
      <ref url="http://secunia.com/advisories/18293" source="SECUNIA" adv="1">18293</ref>
      <ref url="http://evuln.com/vulns/14/summary.html" source="MISC" adv="1">http://evuln.com/vulns/14/summary.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ralph_capper" name="tinyphpforum">
        <vers num="3.46"/>
        <vers num="3.47"/>
        <vers num="3.48"/>
        <vers num="3.49"/>
        <vers num="3.499"/>
        <vers num="3.5"/>
        <vers num="3.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0104" published="2006-01-06" name="CVE-2006-0104" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in TinyPHPForum 3.6 and earlier allows remote attackers to create a new user account, create a new topic, or view the profile of a user account, as demonstrated via a .. (dot dot) in the uname parameter to profile.php.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0054" source="VUPEN">ADV-2006-0054</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/420933/100/0/threaded" source="BUGTRAQ" adv="1">20060105 [eVuln] TinyPHPForum Multiple Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/18293" source="SECUNIA" adv="1">18293</ref>
      <ref url="http://evuln.com/vulns/14/summary.html" source="MISC" adv="1">http://evuln.com/vulns/14/summary.html</ref>
      <ref url="http://evuln.com/vulns/14/exploit.html" source="MISC">http://evuln.com/vulns/14/exploit.html</ref>
      <ref url="http://www.securityfocus.com/bid/16163" source="BID">16163</ref>
      <ref url="http://www.osvdb.org/22258" source="OSVDB">22258</ref>
      <ref url="http://securitytracker.com/id?1015436" source="SECTRACK">1015436</ref>
      <ref url="http://securityreason.com/securityalert/320" source="SREASON">320</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ralph_capper" name="tinyphpforum">
        <vers num="3.46"/>
        <vers num="3.47"/>
        <vers num="3.48"/>
        <vers num="3.49"/>
        <vers num="3.499"/>
        <vers num="3.5"/>
        <vers num="3.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0105" published="2006-01-10" name="CVE-2006-0105" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PostgreSQL 8.0.x before 8.0.6 and 8.1.x before 8.1.2, when running on Windows, allows remote attackers to cause a denial of service (postmaster exit and no new connections) via a large number of simultaneous connection requests.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://archives.postgresql.org/pgsql-announce/2006-01/msg00001.php" source="MLIST" patch="1">[pgsql-announce] 20060109 CRITICAL RELEASE: Minor Releases to Fix DoS Vulnerability</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0114" source="VUPEN">ADV-2006-0114</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24049" source="XF">postgresql-connection-request-dos(24049)</ref>
      <ref url="http://www.securityfocus.com/bid/16201" source="BID">16201</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421592/100/0/threaded" source="BUGTRAQ">20060111 PostgreSQL security releases 8.0.6 and 8.1.2</ref>
      <ref url="http://www.postgresql.org/about/news.456" source="CONFIRM">http://www.postgresql.org/about/news.456</ref>
      <ref url="http://securitytracker.com/id?1015482" source="SECTRACK">1015482</ref>
      <ref url="http://securityreason.com/securityalert/327" source="SREASON">327</ref>
      <ref url="http://secunia.com/advisories/18419" source="SECUNIA">18419</ref>
    </refs>
    <vuln_soft>
      <prod vendor="postgresql" name="postgresql">
        <vers num="8.0"/>
        <vers num="8.0.1"/>
        <vers num="8.0.2"/>
        <vers num="8.0.3"/>
        <vers num="8.0.4"/>
        <vers num="8.0.5"/>
        <vers num="8.1.0"/>
        <vers num="8.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0106" published="2006-01-06" name="CVE-2006-0106" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">gdi/driver.c and gdi/printdrv.c in Wine 20050930, and other versions, implement the SETABORTPROC GDI Escape function call for Windows Metafile (WMF) files, which allows attackers to execute arbitrary code, the same vulnerability as CVE-2005-4560 but in a different codebase.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18323" source="SECUNIA" patch="1" adv="1">18323</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=346197" source="MISC" patch="1">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=346197</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0098" source="VUPEN">ADV-2006-0098</ref>
      <ref url="http://lists.immunitysec.com/pipermail/dailydave/2006-January/002806.html" source="MLIST">[Dailydave] 20060105 WMF goes away :&lt;</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/23846" source="XF">win-wmf-execute-code(23846)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422128/100/0/threaded" source="BUGTRAQ">20060117 ERRATA: [ GLSA 200601-09 ] Wine: Windows Metafile SETABORTPROC vulnerability</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_02_sr.html" source="SUSE">SUSE-SR:2006:002</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:014" source="MANDRIVA">MDKSA-2006:014</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200601-09.xml" source="GENTOO">GLSA-200601-09</ref>
      <ref url="http://www.debian.org/security/2006/dsa-954" source="DEBIAN">DSA-954</ref>
      <ref url="http://secunia.com/advisories/18578" source="SECUNIA">18578</ref>
      <ref url="http://secunia.com/advisories/18549" source="SECUNIA">18549</ref>
      <ref url="http://secunia.com/advisories/18451" source="SECUNIA">18451</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wine" name="wine">
        <vers num="0.9.2"/>
        <vers num="0.9.4"/>
        <vers num="0.9.5"/>
        <vers num="2005-09-30"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0107" published="2006-01-06" name="CVE-2006-0107" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in Timecan CMS allows remote attackers to execute arbitrary SQL commands via the viewID parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  Due to the unavailability of the original source, it cannot be determined if this is the same issue as identified by CVE-2006-0108.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16159" source="BID">16159</ref>
      <ref url="http://www.osvdb.org/22252" source="OSVDB">22252</ref>
      <ref url="http://secunia.com/advisories/18324" source="SECUNIA" adv="1">18324</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24014" source="XF">timecancms-sql-injection(24014)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="idea_development_id_oy" name="timecan_cms">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0108" published="2006-01-06" name="CVE-2006-0108" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in mcl_login.asp in Timecan CMS allows remote attackers to execute arbitrary SQL commands via the email parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  Due to the unavailability of the original source, it cannot be determined if this is the same issue as identified by CVE-2006-0107.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0078" source="VUPEN">ADV-2006-0078</ref>
      <ref url="http://www.osvdb.org/22253" source="OSVDB">22253</ref>
      <ref url="http://www.osvdb.org/22252" source="OSVDB">22252</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24014" source="XF">timecancms-sql-injection(24014)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="idea_development_id_oy" name="timecan_cms">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0109" published="2006-01-06" name="CVE-2006-0109" modified="2011-03-07" discovered="2006-01-06" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability in category.php in Modular Merchant Shopping Cart allows remote attackers to inject arbitrary web script or HTML via the cat parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18320" source="SECUNIA" patch="1" adv="1">18320</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0076" source="VUPEN">ADV-2006-0076</ref>
      <ref url="http://www.securityfocus.com/bid/16160" source="BID">16160</ref>
      <ref url="http://www.osvdb.org/22243" source="OSVDB">22243</ref>
      <ref url="http://www.modularmerchant.com/forums/viewtopic.php?t=46" source="MISC">http://www.modularmerchant.com/forums/viewtopic.php?t=46</ref>
      <ref url="http://osvdb.org/ref/22/22243-modular.txt" source="MISC">http://osvdb.org/ref/22/22243-modular.txt</ref>
      <ref url="http://attrition.org/pipermail/vim/2006-February/000548.html" source="VIM">20060214 vendor ack/fix 22243: Modular Merchant Marketplace Shopping Cart category.php cat Variable XSS (fwd)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="modular_merchant" name="shopping_cart">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0110" published="2006-01-06" name="CVE-2006-0110" modified="2011-03-07" discovered="2006-01-06" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in escribir.php in Foro Domus 2.10 allows remote attackers to inject arbitrary web script via the email parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0073" source="VUPEN">ADV-2006-0073</ref>
      <ref url="http://www.securityfocus.com/bid/16154" source="BID">16154</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421056/100/0/threaded" source="BUGTRAQ">20060106 [eVuln] Proyecto Domus 'email' XSS Vulnerability</ref>
      <ref url="http://www.osvdb.org/22263" source="OSVDB">22263</ref>
      <ref url="http://secunia.com/advisories/18327" source="SECUNIA" adv="1">18327</ref>
      <ref url="http://evuln.com/vulns/16/summary.html" source="MISC">http://evuln.com/vulns/16/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24020" source="XF">domus-escribir-xss(24020)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="javier_suarez_sanz" name="foro_domus">
        <vers num="2.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0111" published="2006-01-06" name="CVE-2006-0111" modified="2011-03-07" discovered="2006-01-06" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability in index.php in Boxcar Media Shopping Cart allows remote attackers to inject arbitrary web script or HTML via the (1) parent or (2) pg parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24019" source="XF">boxcar-index-xss(24019)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0080" source="VUPEN">ADV-2006-0080</ref>
      <ref url="http://www.osvdb.org/22360" source="OSVDB">22360</ref>
      <ref url="http://osvdb.org/ref/22/22360-boxcar.txt" source="MISC">http://osvdb.org/ref/22/22360-boxcar.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="boxcar_media" name="shopping_cart">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0112" published="2006-01-06" name="CVE-2006-0112" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Enhanced Simple PHP Gallery 1.7 allows remote attackers to inject arbitrary web script or HTML via the dir parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0036" source="VUPEN">ADV-2006-0036</ref>
      <ref url="http://www.osvdb.org/22201" source="OSVDB">22201</ref>
      <ref url="http://secunia.com/advisories/18310" source="SECUNIA" adv="1">18310</ref>
      <ref url="http://osvdb.org/ref/22/22201-espg.txt" source="MISC">http://osvdb.org/ref/22/22201-espg.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="enhanced_simple_php_gallery" name="enhanced_simple_php_gallery">
        <vers num="1.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0113" published="2006-01-06" name="CVE-2006-0113" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Enhanced Simple PHP Gallery 1.7 allows remote attackers to obtain the full path of the application via a direct request to sp_helper_functions.php, which leaks the pathname in an error message.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18310" source="SECUNIA" adv="1">18310</ref>
      <ref url="http://osvdb.org/ref/22/22201-espg.txt" source="MISC">http://osvdb.org/ref/22/22201-espg.txt</ref>
      <ref url="http://www.osvdb.org/22417" source="OSVDB">22417</ref>
    </refs>
    <vuln_soft>
      <prod vendor="enhanced_simple_php_gallery" name="enhanced_simple_php_gallery">
        <vers num="1.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0114" published="2006-01-09" name="CVE-2006-0114" modified="2011-06-06" discovered="2006-01-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The vCard functions in Joomla! 1.0.5 use predictable sequential IDs for vcards and do not restrict access to them, which allows remote attackers to obtain valid e-mail addresses to conduct spam attacks by modifying the contact_id parameter to index2.php.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24042" source="XF">joomla-vcard-information-disclosure(24042)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0097" source="VUPEN" adv="1">ADV-2006-0097</ref>
      <ref url="http://www.securityfocus.com/bid/16185" source="BID">16185</ref>
      <ref url="http://secunia.com/advisories/18361" source="SECUNIA" adv="1">18361</ref>
      <ref url="http://forum.joomla.org/index.php/topic,29031.0.html" source="CONFIRM" adv="1">http://forum.joomla.org/index.php/topic,29031.0.html</ref>
      <ref url="http://forge.joomla.org/sf/go/artf2950" source="CONFIRM">http://forge.joomla.org/sf/go/artf2950</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomla" name="joomla">
        <vers num="1.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0115" published="2006-01-09" name="CVE-2006-0115" modified="2011-09-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in OnePlug Solutions OnePlug CMS allow remote attackers to execute arbitrary SQL commands via the (1) Press_Release_ID parameter in press/details.asp, (2) Service_ID parameter in services/details.asp, and (3) Product_ID parameter in products/details.asp.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0079" source="VUPEN" adv="1">ADV-2006-0079</ref>
      <ref url="http://www.securityfocus.com/bid/16155" source="BID">16155</ref>
      <ref url="http://www.osvdb.org/22250" source="OSVDB">22250</ref>
      <ref url="http://www.osvdb.org/22249" source="OSVDB">22249</ref>
      <ref url="http://www.osvdb.org/22248" source="OSVDB">22248</ref>
      <ref url="http://secunia.com/advisories/18325" source="SECUNIA" adv="1">18325</ref>
      <ref url="http://osvdb.org/ref/22/22248-oneplug.txt" source="MISC">http://osvdb.org/ref/22/22248-oneplug.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oneplug_solutions" name="oneplug_cms">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0116" published="2006-01-09" name="CVE-2006-0116" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability search.inetstore in iNETstore Ebusiness Software 2.0 allows remote attackers to inject arbitrary web script or HTML via the searchterm parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0075" source="VUPEN">ADV-2006-0075</ref>
      <ref url="http://www.securityfocus.com/bid/16156" source="BID">16156</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423137/100/0/threaded" source="BUGTRAQ">20060126 Re: [OSVDB Mods] iNETstore E Commerce Solution - Cross Site Scripting</ref>
      <ref url="http://www.osvdb.org/22251" source="OSVDB">22251</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2006-January/000515.html" source="VIM">20060127 vendor confirms versions: iNETstore E Commerce Solution - Cross Site Scripting (fwd)</ref>
      <ref url="http://secunia.com/advisories/18322" source="SECUNIA" adv="1">18322</ref>
      <ref url="http://osvdb.org/ref/22/22251-inetstore.txt" source="MISC">http://osvdb.org/ref/22/22251-inetstore.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="inetstore" name="inetstore_online">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0117" published="2006-01-09" name="CVE-2006-0117" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in IBM Lotus Notes and Domino Server before 6.5.5 allows attackers to cause a denial of service (router crash or hang) via unspecified vectors involving "CD to MIME Conversion".</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16158" source="BID" patch="1">16158</ref>
      <ref url="http://secunia.com/advisories/18328" source="SECUNIA" patch="1" adv="1">18328</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0081" source="VUPEN">ADV-2006-0081</ref>
      <ref url="http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/21d8fd7989fdf78d852570e4001bae68?OpenDocument" source="CONFIRM">http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/21d8fd7989fdf78d852570e4001bae68?OpenDocument</ref>
      <ref url="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/50c634bfe193efa5852570e4001baace?OpenDocument" source="CONFIRM">http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/50c634bfe193efa5852570e4001baace?OpenDocument</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg27007054" source="CONFIRM">http://www-1.ibm.com/support/docview.wss?uid=swg27007054</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24205" source="XF">lotus-cdtomime-dos(24205)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_domino">
        <vers num="6.5.0"/>
        <vers num="6.5.1"/>
        <vers num="6.5.2"/>
        <vers num="6.5.3"/>
        <vers num="6.5.4" edition=""/>
        <vers num="6.5.4" edition=":fp1"/>
        <vers num="6.5.4" edition=":fp2"/>
      </prod>
      <prod vendor="ibm" name="lotus_domino_enterprise_server">
        <vers num="6.5.2"/>
        <vers num="6.5.4"/>
      </prod>
      <prod vendor="ibm" name="lotus_notes">
        <vers num="6.5"/>
        <vers num="6.5.1"/>
        <vers num="6.5.2"/>
        <vers num="6.5.3"/>
        <vers num="6.5.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0118" published="2006-01-09" name="CVE-2006-0118" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in IBM Lotus Notes and Domino Server before 6.5.5, when running on AIX, allows attackers to cause a denial of service (deep recursion leading to stack overflow and crash) via long formulas.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16158" source="BID" patch="1">16158</ref>
      <ref url="http://secunia.com/advisories/18328" source="SECUNIA" patch="1" adv="1">18328</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0081" source="VUPEN">ADV-2006-0081</ref>
      <ref url="http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/21d8fd7989fdf78d852570e4001bae68?OpenDocument" source="CONFIRM">http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/21d8fd7989fdf78d852570e4001bae68?OpenDocument</ref>
      <ref url="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/50c634bfe193efa5852570e4001baace?OpenDocument" source="CONFIRM">http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/50c634bfe193efa5852570e4001baace?OpenDocument</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg27007054" source="CONFIRM">http://www-1.ibm.com/support/docview.wss?uid=swg27007054</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24206" source="XF">lotus-long-formula-bo(24206)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_domino">
        <vers num="6.5.0"/>
        <vers num="6.5.1"/>
        <vers num="6.5.2"/>
        <vers num="6.5.3"/>
        <vers num="6.5.4" edition=""/>
        <vers num="6.5.4" edition=":fp1"/>
        <vers num="6.5.4" edition=":fp2"/>
      </prod>
      <prod vendor="ibm" name="lotus_domino_enterprise_server">
        <vers num="6.5.2"/>
        <vers num="6.5.4"/>
      </prod>
      <prod vendor="ibm" name="lotus_notes">
        <vers num="6.5"/>
        <vers num="6.5.1"/>
        <vers num="6.5.2"/>
        <vers num="6.5.3"/>
        <vers num="6.5.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0119" published="2006-01-09" name="CVE-2006-0119" modified="2011-09-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in IBM Lotus Notes and Domino Server before 6.5.5 have unknown impact and attack vectors, due to "potential security issues" as identified by SPR numbers (1) GPKS6C9J67 in Agents, (2) JGAN6B6TZ3 and (3) KSPR699NBP in the Router, (4) GPKS5YQGPT in Security, or (5) HSAO6BNL6Y in the Web Server. NOTE: vector 3 is related to an issue in NROUTER in IBM Lotus Notes and Domino Server before 6.5.4 FP1, 6.5.5, and 7.0, which allows remote attackers to cause a denial of service (CPU consumption) via a crafted vCal meeting request sent via SMTP (aka SPR# KSPR699NBP).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16158" source="BID" patch="1">16158</ref>
      <ref url="http://secunia.com/advisories/18328" source="SECUNIA" patch="1" adv="1">18328</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/27413" source="XF">domino-smtp-nrouter-dos(27413)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24211" source="XF">lotus-web-unspecified-xss(24211)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24207" source="XF">lotus-multiple-unspecified(24207)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2564" source="VUPEN" adv="1">ADV-2006-2564</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0081" source="VUPEN" adv="1">ADV-2006-0081</ref>
      <ref url="http://www.securityfocus.com/bid/18020" source="BID">18020</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/438461/100/0/threaded" source="BUGTRAQ">20060626 SYMSA-2006-006: Lotus Domino SMTP Based Denial of Service</ref>
      <ref url="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/f97fe7cfd9a8113b8525709200001db4?OpenDocument&amp;Highlight=0,GPKS6C9J67" source="CONFIRM">http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/f97fe7cfd9a8113b8525709200001db4?OpenDocument&amp;Highlight=0,GPKS6C9J67</ref>
      <ref url="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/e4deb1cbb011c747852570e4001ba9bb?OpenDocument&amp;Highlight=0,GPKS5YQGPT" source="CONFIRM">http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/e4deb1cbb011c747852570e4001ba9bb?OpenDocument&amp;Highlight=0,GPKS5YQGPT</ref>
      <ref url="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/de2ab57a5b9547848525701b00420c2c?OpenDocument&amp;Highlight=0,KSPR699NBP" source="CONFIRM">http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/de2ab57a5b9547848525701b00420c2c?OpenDocument&amp;Highlight=0,KSPR699NBP</ref>
      <ref url="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/d1150fc9c5dec8b18525709200001da6?OpenDocument&amp;Highlight=0,GPKS6C9J67" source="CONFIRM">http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/d1150fc9c5dec8b18525709200001da6?OpenDocument&amp;Highlight=0,GPKS6C9J67</ref>
      <ref url="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/9a1650d1a771f3078525702a00420def?OpenDocument&amp;Highlight=0,HSAO6BNL6Y" source="CONFIRM">http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/9a1650d1a771f3078525702a00420def?OpenDocument&amp;Highlight=0,HSAO6BNL6Y</ref>
      <ref url="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/94a77eb898843aca8525709200001de1?OpenDocument&amp;Highlight=0,JGAN6B6TZ3" source="CONFIRM">http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/94a77eb898843aca8525709200001de1?OpenDocument&amp;Highlight=0,JGAN6B6TZ3</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg27007054" source="CONFIRM">http://www-1.ibm.com/support/docview.wss?uid=swg27007054</ref>
      <ref url="http://securitytracker.com/id?1016390" source="SECTRACK">1016390</ref>
      <ref url="http://secunia.com/advisories/20855" source="SECUNIA" adv="1">20855</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_domino">
        <vers num="6.5.0"/>
        <vers num="6.5.1"/>
        <vers num="6.5.2"/>
        <vers num="6.5.3"/>
        <vers num="6.5.4" edition=""/>
        <vers num="6.5.4" edition=":fp1"/>
        <vers num="6.5.4" edition=":fp2"/>
      </prod>
      <prod vendor="ibm" name="lotus_domino_enterprise_server">
        <vers num="6.5.2"/>
        <vers num="6.5.4"/>
      </prod>
      <prod vendor="ibm" name="lotus_notes">
        <vers num="6.5"/>
        <vers num="6.5.1"/>
        <vers num="6.5.2"/>
        <vers num="6.5.3"/>
        <vers num="6.5.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0120" published="2006-01-09" name="CVE-2006-0120" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in IBM Lotus Notes and Domino Server before 6.5.5 allow attackers to cause a denial of service (application crash) via multiple vectors, involving (1) a malformed message sent to an "Out Of Office" agent (SPR LPEE6DMQWJ), (2) the compact command (RTIN5U2SAJ), (3) malformed bitmap images (MYAA6FH5HW), (4) the "Delete Attachment" action (YPHG6844LD), (5) parsing certificates from a remote Certificate Table (AELE6DZFJW), and (6) creating a SSL key ring with the Domino Administration client (NSUA4FQPTN).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16158" source="BID" patch="1">16158</ref>
      <ref url="http://secunia.com/advisories/18328" source="SECUNIA" patch="1" adv="1">18328</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0081" source="VUPEN">ADV-2006-0081</ref>
      <ref url="http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/ced5f873baea4e8b852570e4001baa6d?OpenDocument" source="CONFIRM">http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/ced5f873baea4e8b852570e4001baa6d?OpenDocument</ref>
      <ref url="http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/ad0dd14aa109f96b852570e4001bb08c?OpenDocument" source="CONFIRM">http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/ad0dd14aa109f96b852570e4001bb08c?OpenDocument</ref>
      <ref url="http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/5f166a44ee743b2c852570e4001baf31?OpenDocument" source="CONFIRM">http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/5f166a44ee743b2c852570e4001baf31?OpenDocument</ref>
      <ref url="http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/4118a1f266afb26c852570e4001baf5e?OpenDocument" source="CONFIRM">http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/4118a1f266afb26c852570e4001baf5e?OpenDocument</ref>
      <ref url="http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/2bb4f466a9e986ae852570e4001babbb?OpenDocument" source="CONFIRM">http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/2bb4f466a9e986ae852570e4001babbb?OpenDocument</ref>
      <ref url="http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/040482aeb1416bb7852570e4001badd6?OpenDocument" source="CONFIRM">http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/040482aeb1416bb7852570e4001badd6?OpenDocument</ref>
      <ref url="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/258394eaa824f2c08525708a004209d3?OpenDocument" source="CONFIRM">http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/258394eaa824f2c08525708a004209d3?OpenDocument</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg27007054" source="CONFIRM">http://www-1.ibm.com/support/docview.wss?uid=swg27007054</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24217" source="XF">lotus-ssl-keyring-dos(24217)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24216" source="XF">lotus-certificate-parsing-dos(24216)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24215" source="XF">lotus-delete-attachment-dos(24215)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24214" source="XF">lotus-bmp-dos(24214)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24213" source="XF">lotus-compact-dos(24213)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24212" source="XF">lotus-outofoffice-dos(24212)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_domino">
        <vers num="6.5.0"/>
        <vers num="6.5.1"/>
        <vers num="6.5.2"/>
        <vers num="6.5.3"/>
        <vers num="6.5.4" edition=""/>
        <vers num="6.5.4" edition=":fp1"/>
        <vers num="6.5.4" edition=":fp2"/>
      </prod>
      <prod vendor="ibm" name="lotus_domino_enterprise_server">
        <vers num="6.5.2"/>
        <vers num="6.5.4"/>
      </prod>
      <prod vendor="ibm" name="lotus_notes">
        <vers num="6.5"/>
        <vers num="6.5.1"/>
        <vers num="6.5.2"/>
        <vers num="6.5.3"/>
        <vers num="6.5.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0121" published="2006-01-09" name="CVE-2006-0121" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Multiple memory leaks in IBM Lotus Notes and Domino Server before 6.5.5 allow attackers to cause a denial of service (memory consumption and crash) via unknown vectors related to (1) unspecified vectors during the SSL handshake (SPR# MKIN67MQVW), (2) the stash file during the SSL handshake (SPR# MKIN693QUT), and possibly other vectors. NOTE: due to insufficient information in the original vendor advisory, it is not clear whether there is an attacker role in other memory leaks that are specified in the advisory.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16158" source="BID" patch="1">16158</ref>
      <ref url="http://secunia.com/advisories/18328" source="SECUNIA" patch="1" adv="1">18328</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0081" source="VUPEN">ADV-2006-0081</ref>
      <ref url="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/2221243535d88a2b8525701b00420cd6?OpenDocument&amp;Highlight=0,MKIN693QUT" source="CONFIRM">http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/2221243535d88a2b8525701b00420cd6?OpenDocument&amp;Highlight=0,MKIN693QUT</ref>
      <ref url="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/20f66e356a76c90f8525702a00420e08?OpenDocument&amp;Highlight=0,MKIN67MQVW" source="CONFIRM">http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/20f66e356a76c90f8525702a00420e08?OpenDocument&amp;Highlight=0,MKIN67MQVW</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg27007054" source="CONFIRM">http://www-1.ibm.com/support/docview.wss?uid=swg27007054</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24223" source="XF">lotus-ssl-handshake-dos(24223)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_domino">
        <vers num="6.5.0"/>
        <vers num="6.5.1"/>
        <vers num="6.5.2"/>
        <vers num="6.5.3"/>
        <vers num="6.5.4" edition=""/>
        <vers num="6.5.4" edition=":fp1"/>
        <vers num="6.5.4" edition=":fp2"/>
      </prod>
      <prod vendor="ibm" name="lotus_domino_enterprise_server">
        <vers num="6.5.2"/>
        <vers num="6.5.4"/>
      </prod>
      <prod vendor="ibm" name="lotus_notes">
        <vers num="6.5"/>
        <vers num="6.5.1"/>
        <vers num="6.5.2"/>
        <vers num="6.5.3"/>
        <vers num="6.5.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0122" published="2006-01-09" name="CVE-2006-0122" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Public/Index.asp in Aquifer CMS allows remote attackers to inject arbitrary web script or HTML via the Keyword parameter.</descript>
    </desc>
    <sols>
      <sol source="nvd">Vendor provided solution:

"Liquid Development has identified this vulnerability in all shipping versions of AquiferCMS and coded a software fix. The fix will be included in all releases of AquiferCMS built on or after January 24, 2006. Customers should contact Liquid Development to obtain the fix for this vulnerability.  For more information visit www.aquifercms.com." 
</sol>
    </sols>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.osvdb.org/22247" source="OSVDB" patch="1">22247</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0074" source="VUPEN">ADV-2006-0074</ref>
      <ref url="http://www.securityfocus.com/bid/16162" source="BID">16162</ref>
      <ref url="http://secunia.com/advisories/18326" source="SECUNIA" adv="1">18326</ref>
      <ref url="http://osvdb.org/ref/22/22247-aquifer.txt" source="MISC">http://osvdb.org/ref/22/22247-aquifer.txt</ref>
      <ref url="http://attrition.org/pipermail/vim/2006-January/000509.html" source="VIM">20060124 vendor ack/fix: Aquifer CMS Index.asp Keyword Variable XSS (fwd)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aquifer_cms" name="aquifer_cms">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0123" published="2006-01-09" name="CVE-2006-0123" modified="2011-09-08" discovered="2006-01-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in ADN Forum 1.0b allow remote attackers to execute arbitrary SQL commands via the (1) fid parameter in index.php and (2) pagid parameter in verpag.php, and possibly other vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0077" source="VUPEN" adv="1">ADV-2006-0077</ref>
      <ref url="http://www.securityfocus.com/bid/16157" source="BID">16157</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/420990/100/0/threaded" source="BUGTRAQ" adv="1">20060105 [eVuln] ADNForum Multiple Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/22241" source="OSVDB">22241</ref>
      <ref url="http://www.osvdb.org/22240" source="OSVDB">22240</ref>
      <ref url="http://securitytracker.com/id?1015445" source="SECTRACK">1015445</ref>
      <ref url="http://secunia.com/advisories/18300" source="SECUNIA" adv="1">18300</ref>
      <ref url="http://evuln.com/vulns/15/summary.html" source="MISC" adv="1">http://evuln.com/vulns/15/summary.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adn_forum" name="adn_forum">
        <vers num="1.0"/>
        <vers num="1.0b"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0124" published="2006-01-09" name="CVE-2006-0124" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in crear.php in ADN Forum 1.0b allows remote attackers to inject arbitrary web script or HTML via the titulo parameter, which is used by the "Topic name" field.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0077" source="VUPEN">ADV-2006-0077</ref>
      <ref url="http://www.securityfocus.com/bid/16157" source="BID">16157</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/420990/100/0/threaded" source="BUGTRAQ" adv="1">20060105 [eVuln] ADNForum Multiple Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/18300" source="SECUNIA" adv="1">18300</ref>
      <ref url="http://evuln.com/vulns/15/summary.html" source="MISC" adv="1">http://evuln.com/vulns/15/summary.html</ref>
      <ref url="http://www.osvdb.org/22242" source="OSVDB">22242</ref>
      <ref url="http://securitytracker.com/id?1015445" source="SECTRACK">1015445</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adn_forum" name="adn_forum">
        <vers num="1.0"/>
        <vers num="1.0b"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0125" published="2006-01-09" name="CVE-2006-0125" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in appserv/main.php in AppServ 2.4.5 allows remote attackers to include arbitrary files via the appserv_root parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  There is not enough detail from these third party sources to know whether this is directory traversal, remote file include, or another issue.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0053" source="VUPEN">ADV-2006-0053</ref>
      <ref url="http://www.osvdb.org/22228" source="OSVDB">22228</ref>
      <ref url="http://secunia.com/advisories/18163" source="SECUNIA" adv="1">18163</ref>
      <ref url="http://www.securityfocus.com/bid/16166" source="BID">16166</ref>
    </refs>
    <vuln_soft>
      <prod vendor="appserv_open_project" name="appserv">
        <vers num="2.4.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0126" published="2006-01-09" name="CVE-2006-0126" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">rxvt-unicode before 6.3, on certain platforms that use openpty and non-Unix pty devices such as Linux and most BSD platforms, does not maintain the intended permissions of tty devices, which allows local users to gain read and write access to the devices.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.osvdb.org/22223" source="OSVDB" patch="1">22223</ref>
      <ref url="http://secunia.com/advisories/18301" source="SECUNIA" patch="1" adv="1">18301</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0052" source="VUPEN">ADV-2006-0052</ref>
      <ref url="http://dist.schmorp.de/rxvt-unicode/Changes" source="CONFIRM">http://dist.schmorp.de/rxvt-unicode/Changes</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rxvt-unicode" name="rxvt-unicode">
        <vers prev="1" num="6.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0127" published="2006-01-09" name="CVE-2006-0127" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the IMAP service of Rockliffe MailSite before 6.1.22.1 allows remote authenticated users to rename the folders of other users via a .. (dot dot) in the RENAME command.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://zur.homelinux.com/Advisories/RockliffeMailsiteDirTransveral.txt" source="MISC" patch="1" adv="1">http://zur.homelinux.com/Advisories/RockliffeMailsiteDirTransveral.txt</ref>
      <ref url="http://www.osvdb.org/22229" source="OSVDB" patch="1">22229</ref>
      <ref url="http://secunia.com/advisories/18318" source="SECUNIA" patch="1" adv="1">18318</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/040969.html" source="FULLDISC" patch="1" adv="1">20060104 Rockliffe Directory Transversal Vulnerability</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0055" source="VUPEN">ADV-2006-0055</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041039.html" source="FULLDISC">20060105 Re: Rockliffe Directory Transversal Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rockliffe" name="mailsite">
        <vers prev="1" num="6.1.22.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0128" published="2006-01-09" name="CVE-2006-0128" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the IMAP service of Rockliffe MailSite before 6.1.22.1 allows remote attackers to have an unknown impact via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://zur.homelinux.com/Advisories/RockliffeMailsiteDirTransveral.txt" source="MISC" patch="1" adv="1">http://zur.homelinux.com/Advisories/RockliffeMailsiteDirTransveral.txt</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/040969.html" source="FULLDISC" patch="1" adv="1">20060104 Rockliffe Directory Transversal Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39991" source="XF">rockliffe-imap-unspecified-bo(39991)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rockliffe" name="mailsite">
        <vers prev="1" num="6.1.22.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0129" published="2006-01-09" name="CVE-2006-0129" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Mail Management Agent (MAILMA) (aka Mail Management Server) in Rockliffe MailSite 7.0.3.1 and earlier generates different responses depending on whether or not a username is valid, which allows remote attackers to enumerate valid usernames via user requests to TCP port 106.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18318" source="SECUNIA" patch="1" adv="1">18318</ref>
      <ref url="http://zur.homelinux.com/Advisories/RockliffeMailsiteUserEnum.txt" source="MISC" adv="1">http://zur.homelinux.com/Advisories/RockliffeMailsiteUserEnum.txt</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0055" source="VUPEN">ADV-2006-0055</ref>
      <ref url="http://www.osvdb.org/22230" source="OSVDB">22230</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/040970.html" source="FULLDISC" adv="1">20060104 Rockliffe Mailsite User Enumeration Flaw</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rockliffe" name="mailsite">
        <vers prev="1" num="7.0.3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0130" published="2006-01-09" name="CVE-2006-0130" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Mail Management Agent (MAILMA) (aka Mail Management Server) in Rockliffe MailSite 7.0.3.1 and earlier allows remote attackers to attempt authentication with an unlimited number of user account names and passwords without denying connections, limiting the rate of connections, or locking out an account.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://zur.homelinux.com/Advisories/RockliffeMailsiteUserEnum.txt" source="MISC" adv="1">http://zur.homelinux.com/Advisories/RockliffeMailsiteUserEnum.txt</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/040970.html" source="FULLDISC" adv="1">20060104 Rockliffe Mailsite User Enumeration Flaw</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rockliffe" name="mailsite">
        <vers prev="1" num="7.0.3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0131" published="2006-01-09" name="CVE-2006-0131" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">boastMachine 3.1 allows remote attackers to obtain sensitive information via a direct request to (1) footer.php and (2) side_menu.php, which reveals the path in an error message.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/420969/100/0/threaded" source="BUGTRAQ" adv="1">20060105 [ECHO_ADV_25$2006] Full path disclosure on boastMachine v3.1</ref>
      <ref url="http://echo.or.id/adv/adv26-K-159-2006.txt" source="MISC">http://echo.or.id/adv/adv26-K-159-2006.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="boastmachine" name="boastmachine">
        <vers num="3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0132" published="2006-01-09" name="CVE-2006-0132" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in webftp.php in SysCP WebFTP 1.2.6 and possibly earlier allows remote attackers to include and execute arbitrary local PHP scripts, and possibly read other types of files, via a .. (dot dot) and a trailing null in the webftp_language parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18355" source="SECUNIA" patch="1" adv="1">18355</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0090" source="VUPEN">ADV-2006-0090</ref>
      <ref url="http://www.securityfocus.com/bid/16175" source="BID">16175</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/420973/100/0/threaded" source="BUGTRAQ">20060104 SysCP WebFTP local file inclusion vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24018" source="XF">webftp-language-file-include(24018)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webftp" name="webftp">
        <vers num="1.2.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0133" published="2006-01-09" name="CVE-2006-0133" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in AIX 5.3 ML03 allow local users to determine the existence of files and read partial contents of certain files via a .. (dot dot) in the argument to (1) getCommand.new (aka getCommand) and (2) getShell, a different vulnerability than CVE-2005-4273.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16103" source="BID">16103</ref>
      <ref url="http://www.securityfocus.com/bid/16102" source="BID">16102</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/420589/100/0/threaded" source="BUGTRAQ" adv="1">20060101 [xfocus-SD-060101]AIX getCommand&amp;getShell two vulnerabilities</ref>
      <ref url="http://securitytracker.com/id?1015429" source="SECTRACK">1015429</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="5.3_ml03"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0134" published="2006-01-09" name="CVE-2006-0134" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in register.php in TheWebForum (twf) 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the www parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0093" source="VUPEN">ADV-2006-0093</ref>
      <ref url="http://www.securityfocus.com/bid/16161" source="BID">16161</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421039/100/0/threaded" source="BUGTRAQ">20060106 [eVuln] TheWebForum Script Insertion and Authentication Bypass</ref>
      <ref url="http://securitytracker.com/id?1015450" source="SECTRACK">1015450</ref>
      <ref url="http://secunia.com/advisories/18392" source="SECUNIA" adv="1">18392</ref>
      <ref url="http://evuln.com/vulns/17/summary.html" source="MISC">http://evuln.com/vulns/17/summary.html</ref>
      <ref url="http://evuln.com/vulns/17/exploit.html" source="MISC">http://evuln.com/vulns/17/exploit.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24007" source="XF">thewebforum-register-xss(24007)</ref>
      <ref url="http://www.osvdb.org/22295" source="OSVDB">22295</ref>
    </refs>
    <vuln_soft>
      <prod vendor="thewebforum" name="thewebforum">
        <vers prev="1" num="1.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0135" published="2006-01-09" name="CVE-2006-0135" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in login.php in TheWebForum (twf) 1.2.1 allows remote attackers to execute arbitrary SQL commands and bypass login authentication via the username parameter (aka the u variable).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0093" source="VUPEN">ADV-2006-0093</ref>
      <ref url="http://www.securityfocus.com/bid/16161" source="BID">16161</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421039/100/0/threaded" source="BUGTRAQ">20060106 [eVuln] TheWebForum Script Insertion and Authentication Bypass</ref>
      <ref url="http://securitytracker.com/id?1015450" source="SECTRACK">1015450</ref>
      <ref url="http://secunia.com/advisories/18392" source="SECUNIA" adv="1">18392</ref>
      <ref url="http://evuln.com/vulns/17/summary.html" source="MISC">http://evuln.com/vulns/17/summary.html</ref>
      <ref url="http://evuln.com/vulns/17/exploit.html" source="MISC">http://evuln.com/vulns/17/exploit.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24027" source="XF">thewebforum-login-sql-injection(24027)</ref>
      <ref url="http://www.osvdb.org/22294" source="OSVDB">22294</ref>
      <ref url="http://securityreason.com/securityalert/321" source="SREASON">321</ref>
    </refs>
    <vuln_soft>
      <prod vendor="thewebforum" name="thewebforum">
        <vers prev="1" num="1.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0136" published="2006-01-09" name="CVE-2006-0136" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the guestbook module in modules.php in Phanatic Softwares Chimera Web Portal System 0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) comment_poster, (2) comment_poster_email, (3) comment_poster_homepage, and (4) comment_text parameters.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0025" source="VUPEN">ADV-2006-0025</ref>
      <ref url="http://www.securityfocus.com/bid/16113" source="BID">16113</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/420669/100/0/threaded" source="BUGTRAQ">20060101 [eVuln] Chimera Web Portal System Multiple Vulnerabilities</ref>
      <ref url="http://evuln.com/vulns/7/summary.html" source="MISC">http://evuln.com/vulns/7/summary.html</ref>
      <ref url="http://evuln.com/vulns/7/exploit.html" source="MISC">http://evuln.com/vulns/7/exploit.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phanatic_softwares" name="chimera_web_portal">
        <vers num="0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0137" published="2006-01-09" name="CVE-2006-0137" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in linkcategory.php in Phanatic Softwares Chimera Web Portal System 0.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0025" source="VUPEN">ADV-2006-0025</ref>
      <ref url="http://www.securityfocus.com/bid/16113" source="BID">16113</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/420669/100/0/threaded" source="BUGTRAQ">20060101 [eVuln] Chimera Web Portal System Multiple Vulnerabilities</ref>
      <ref url="http://evuln.com/vulns/7/summary.html" source="MISC">http://evuln.com/vulns/7/summary.html</ref>
      <ref url="http://evuln.com/vulns/7/exploit.html" source="MISC">http://evuln.com/vulns/7/exploit.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/23963" source="XF">chimera-linkcategory-sql-injection(23963)</ref>
      <ref url="http://www.osvdb.org/22420" source="OSVDB">22420</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phanatic_softwares" name="chimera_web_portal">
        <vers num="0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0138" published="2006-01-09" name="CVE-2006-0138" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">aMSN (aka Alvaro's Messenger) allows remote attackers to cause a denial of service (client hang and termination of client's instant-messaging session) by repeatedly sending crafted data to the default file-transfer port (TCP 6891).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securiteam.com/exploits/5JP090KHFQ.html" source="MISC" adv="1">http://www.securiteam.com/exploits/5JP090KHFQ.html</ref>
      <ref url="http://www.osvdb.org/22186" source="OSVDB">22186</ref>
    </refs>
    <vuln_soft>
      <prod vendor="amsn" name="amsn">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0139" published="2006-01-09" name="CVE-2006-0139" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The send-private-message functionality (send-private-message.asp) in PD9 Software MegaBBS 2.1 allows remote attackers to read private messages of other users via a modified replyid parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16168" source="BID" patch="1">16168</ref>
      <ref url="http://www.pd9soft.com/megabbs/forums/thread-view.asp?tid=4924" source="CONFIRM" patch="1" adv="1">http://www.pd9soft.com/megabbs/forums/thread-view.asp?tid=4924</ref>
      <ref url="http://www.hamid.ir/security/megabbs.txt" source="MISC" patch="1" adv="1">http://www.hamid.ir/security/megabbs.txt</ref>
      <ref url="http://secunia.com/advisories/18342" source="SECUNIA" patch="1" adv="1">18342</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0095" source="VUPEN">ADV-2006-0095</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24050" source="XF">megabbs-sendprivatemessage-disclosure(24050)</ref>
      <ref url="http://securitytracker.com/id?1015452" source="SECTRACK">1015452</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pd9_software" name="megabbs">
        <vers num="2.0"/>
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0140" published="2006-01-09" name="CVE-2006-0140" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in post.php in NavBoard V16 Stable(2.6.0) and V17beta2 allows remote attackers to inject arbitrary web script or HTML via the (1) b, (2) textlarge, and (3) url bbcode tags.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24021" source="XF">navboard-post-xss(24021)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0092" source="VUPEN">ADV-2006-0092</ref>
      <ref url="http://www.securityfocus.com/bid/16165" source="BID">16165</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421149/100/0/threaded" source="BUGTRAQ" adv="1">20060107 [eVuln] NavBoard BBcode XSS Vulnerability</ref>
      <ref url="http://www.osvdb.org/22277" source="OSVDB">22277</ref>
      <ref url="http://secunia.com/advisories/18345" source="SECUNIA" adv="1">18345</ref>
      <ref url="http://evuln.com/vulns/19/summary.html" source="MISC" adv="1">http://evuln.com/vulns/19/summary.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="navboard" name="navboard">
        <vers num="16"/>
        <vers num="17" edition="beta2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0141" published="2006-01-09" name="CVE-2006-0141" modified="2011-03-07" discovered="2006-01-09" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Qualcomm Eudora Internet Mail Server (EIMS) before 3.2.8 allows remote attackers to cause a denial of service (crash) via (1) malformed NTLM authentication requests, or a malformed (2) Incoming Mail X or (3) Temporary Mail file.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.eudora.co.nz/updates.html" source="CONFIRM" patch="1">http://www.eudora.co.nz/updates.html</ref>
      <ref url="http://secunia.com/advisories/18356" source="SECUNIA" patch="1" adv="1">18356</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0099" source="VUPEN">ADV-2006-0099</ref>
      <ref url="http://www.securityfocus.com/bid/16179" source="BID">16179</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24033" source="XF">eims-corrupted-mail-dos(24033)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24032" source="XF">eims-ntlm-auth-dos(24032)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="eudora" name="internet_mail_server">
        <vers num="3.2.6"/>
        <vers num="3.2.7"/>
        <vers num="3.2.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0142" published="2006-01-09" name="CVE-2006-0142" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in andromeda.php in Andromeda 1.9.3.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the s parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0096" source="VUPEN">ADV-2006-0096</ref>
      <ref url="http://www.securityfocus.com/bid/16183" source="BID">16183</ref>
      <ref url="http://secunia.com/advisories/18359" source="SECUNIA" adv="1">18359</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24031" source="XF">andromeda-script-xss(24031)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="andromeda_software" name="andromeda">
        <vers prev="1" num="1.9.3.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0143" published="2006-01-09" name="CVE-2006-0143" modified="2011-09-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Microsoft Windows Graphics Rendering Engine (GRE) allows remote attackers to corrupt memory and cause a denial of service (crash) via a WMF file containing (1) ExtCreateRegion or (2) ExtEscape function calls with arguments with inconsistent lengths.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1015453" source="SECTRACK" patch="1">1015453</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24044" source="XF">win-gre-wmf-dos(24044)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0115" source="VUPEN" adv="1">ADV-2006-0115</ref>
      <ref url="http://www.securityfocus.com/bid/16167" source="BID">16167</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421258/100/0/threaded" source="BUGTRAQ" adv="1">20060109 [UPDATE]Microsoft Windows GRE WMF Format Multiple Unauthorized Memory Access Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421257/100/0/threaded" source="BUGTRAQ" adv="1">20060107 Microsoft Windows GRE WMF Format Multiple Memory Overrun Vulnerabilities</ref>
      <ref url="http://lostmon.blogspot.com/2007/08/windows-extended-file-attributes-buffer.html" source="MISC">http://lostmon.blogspot.com/2007/08/windows-extended-file-attributes-buffer.html</ref>
      <ref url="http://blogs.technet.com/msrc/archive/2006/01/09/417198.aspx" source="CONFIRM">http://blogs.technet.com/msrc/archive/2006/01/09/417198.aspx</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition=":advanced_server"/>
        <vers num="" edition=":professional"/>
        <vers num="" edition=":datacenter_server"/>
        <vers num="" edition=":server"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:datacenter_server"/>
        <vers num="" edition="sp1:professional"/>
        <vers num="" edition="sp1:server"/>
        <vers num="" edition="sp1:advanced_server"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:advanced_server"/>
        <vers num="" edition="sp2:professional"/>
        <vers num="" edition="sp2:datacenter_server"/>
        <vers num="" edition="sp2:server"/>
        <vers num="" edition="sp3"/>
        <vers num="" edition="sp3:datacenter_server"/>
        <vers num="" edition="sp3:server"/>
        <vers num="" edition="sp3:professional"/>
        <vers num="" edition="sp3:advanced_server"/>
        <vers num="" edition="sp4"/>
        <vers num="" edition="sp4:server"/>
        <vers num="" edition="sp4:datacenter_server"/>
        <vers num="" edition="sp4:professional"/>
        <vers num="" edition="sp4:advanced_server"/>
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="datacenter_64-bit" edition="sp1"/>
        <vers num="enterprise" edition=""/>
        <vers num="enterprise" edition=":64-bit"/>
        <vers num="enterprise" edition="sp1"/>
        <vers num="enterprise_64-bit" edition="sp1"/>
        <vers num="r2" edition=""/>
        <vers num="r2" edition=":64-bit"/>
        <vers num="r2" edition=":datacenter_64-bit"/>
        <vers num="r2" edition="sp1"/>
        <vers num="standard" edition=""/>
        <vers num="standard" edition=":64-bit"/>
        <vers num="standard" edition="sp1"/>
        <vers num="standard_64-bit"/>
        <vers num="web" edition="sp1"/>
      </prod>
      <prod vendor="microsoft" name="windows_98">
        <vers num="" edition="gold"/>
      </prod>
      <prod vendor="microsoft" name="windows_98se">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_me">
        <vers num=""/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":media_center"/>
        <vers num="" edition=":home"/>
        <vers num="" edition=":64-bit"/>
        <vers num="" edition="gold"/>
        <vers num="" edition="gold:professional"/>
        <vers num="" edition="sp1"/>
        <vers num="" edition="sp1:home"/>
        <vers num="" edition="sp1:media_center"/>
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp2:home"/>
        <vers num="" edition="sp2:media_center"/>
        <vers num="" edition="sp2:tablet_pc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0144" published="2006-01-09" name="CVE-2006-0144" modified="2011-06-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The proxy server feature in go-pear.php in PHP PEAR 0.2.2, as used in Apache2Triad, allows remote attackers to execute arbitrary PHP code by redirecting go-pear.php to a malicious proxy server that provides a modified version of Tar.php with a malicious extractModify function.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18390" source="SECUNIA" patch="1" adv="1">18390</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24076" source="XF">gopear-proxy-redirection(24076)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0148" source="VUPEN" adv="1">ADV-2006-0148</ref>
      <ref url="http://www.securityfocus.com/bid/16174" source="BID">16174</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421469/100/0/threaded" source="BUGTRAQ">20060109 New PEAR / Apache2Triad Exploit</ref>
      <ref url="http://apache2triad.net/forums/viewtopic.php?p=14670" source="CONFIRM">http://apache2triad.net/forums/viewtopic.php?p=14670</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache2triad" name="apache2triad">
        <vers num=""/>
      </prod>
      <prod vendor="php" name="pear">
        <vers num="0.2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0145" published="2006-01-09" name="CVE-2006-0145" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The kernfs_xread function in kernfs in NetBSD 1.6 through 2.1, and OpenBSD 3.8, does not properly validate file offsets against negative 32-bit values that occur as a result of truncation, which allows local users to read arbitrary kernel memory and gain privileges via the lseek system call.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input/>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16173" source="BID" patch="1">16173</ref>
      <ref url="http://www.securitylab.net/research/2006/02/advisory_netbsd_openbsd_kernfs.html" source="MISC" adv="1">http://www.securitylab.net/research/2006/02/advisory_netbsd_openbsd_kernfs.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423827/100/0/threaded" source="BUGTRAQ">20060202 [SLAB] NetBSD / OpenBSD kernfs_xread patch evasion</ref>
      <ref url="http://www.osvdb.org/22293" source="OSVDB">22293</ref>
      <ref url="http://secunia.com/advisories/18712" source="SECUNIA" adv="1">18712</ref>
      <ref url="http://secunia.com/advisories/18388" source="SECUNIA" adv="1">18388</ref>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2006-001.txt.asc" source="NETBSD">NetBSD-SA2006-001</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24035" source="XF">netbsd-kernfs-memory-disclosure(24035)</ref>
      <ref url="http://securityreason.com/securityalert/405" source="SREASON">405</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netbsd" name="netbsd">
        <vers num="1.6" edition="beta"/>
        <vers num="1.6.1"/>
        <vers num="1.6.2"/>
        <vers num="2.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0146" published="2006-01-09" name="CVE-2006-0146" modified="2011-06-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PHPOpenChat, (7) MAXdev MD-Pro, and (8) MediaBeez, when the MySQL root password is empty, allows remote attackers to execute arbitrary SQL commands via the sql parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.xaraya.com/index.php/news/569" source="CONFIRM" patch="1">http://www.xaraya.com/index.php/news/569</ref>
      <ref url="http://www.securityfocus.com/bid/16187" source="BID" patch="1">16187</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423784/100/0/threaded" source="BUGTRAQ" patch="1">20060202 Bug for libs in php link directory 2.0</ref>
      <ref url="http://www.osvdb.org/22290" source="OSVDB" patch="1">22290</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-07.xml" source="GENTOO" patch="1" adv="1">GLSA-200604-07</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1031" source="DEBIAN" patch="1" adv="1">DSA-1031</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1030" source="DEBIAN" patch="1" adv="1">DSA-1030</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1029" source="DEBIAN" patch="1" adv="1">DSA-1029</ref>
      <ref url="http://secunia.com/secunia_research/2005-64/advisory/" source="MISC" patch="1" adv="1">http://secunia.com/secunia_research/2005-64/advisory/</ref>
      <ref url="http://secunia.com/advisories/19699" source="SECUNIA" patch="1" adv="1">19699</ref>
      <ref url="http://secunia.com/advisories/19591" source="SECUNIA" patch="1" adv="1">19591</ref>
      <ref url="http://secunia.com/advisories/19590" source="SECUNIA" patch="1" adv="1">19590</ref>
      <ref url="http://secunia.com/advisories/19563" source="SECUNIA" patch="1" adv="1">19563</ref>
      <ref url="http://secunia.com/advisories/19555" source="SECUNIA" patch="1" adv="1">19555</ref>
      <ref url="http://secunia.com/advisories/18720" source="SECUNIA" patch="1" adv="1">18720</ref>
      <ref url="http://secunia.com/advisories/18276" source="SECUNIA" patch="1" adv="1">18276</ref>
      <ref url="http://secunia.com/advisories/18260" source="SECUNIA" patch="1" adv="1">18260</ref>
      <ref url="http://secunia.com/advisories/18233" source="SECUNIA" patch="1" adv="1">18233</ref>
      <ref url="http://secunia.com/advisories/17418" source="SECUNIA" patch="1" adv="1">17418</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24051" source="XF">adodb-server-command-execution(24051)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1419" source="VUPEN">ADV-2006-1419</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1305" source="VUPEN" adv="1">ADV-2006-1305</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1304" source="VUPEN" adv="1">ADV-2006-1304</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0447" source="VUPEN" adv="1">ADV-2006-0447</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0370" source="VUPEN" adv="1">ADV-2006-0370</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0105" source="VUPEN" adv="1">ADV-2006-0105</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0104" source="VUPEN" adv="1">ADV-2006-0104</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0103" source="VUPEN" adv="1">ADV-2006-0103</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0102" source="VUPEN">ADV-2006-0102</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0101" source="VUPEN" adv="1">ADV-2006-0101</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/466171/100/0/threaded" source="BUGTRAQ">20070418 MediaBeez Sql query Execution .. Wear isn't ?? :)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430448/100/0/threaded" source="BUGTRAQ">20060409 PhpOpenChat 3.0.x ADODB Server.php </ref>
      <ref url="http://www.maxdev.com/Article550.phtml" source="CONFIRM">http://www.maxdev.com/Article550.phtml</ref>
      <ref url="http://securityreason.com/securityalert/713" source="SREASON">713</ref>
      <ref url="http://secunia.com/advisories/24954" source="SECUNIA" adv="1">24954</ref>
      <ref url="http://secunia.com/advisories/19691" source="SECUNIA" adv="1">19691</ref>
      <ref url="http://secunia.com/advisories/19600" source="SECUNIA" adv="1">19600</ref>
      <ref url="http://secunia.com/advisories/18267" source="SECUNIA" adv="1">18267</ref>
      <ref url="http://secunia.com/advisories/18254" source="SECUNIA" adv="1">18254</ref>
      <ref url="http://retrogod.altervista.org/phpopenchat_30x_sql_xpl.html" source="MISC">http://retrogod.altervista.org/phpopenchat_30x_sql_xpl.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="john_lim" name="adodb">
        <vers num="4.66"/>
        <vers num="4.68"/>
      </prod>
      <prod vendor="mantis" name="mantis">
        <vers num="0.19.4"/>
        <vers num="1.0.0_rc4"/>
      </prod>
      <prod vendor="mediabeez" name="mediabeez">
        <vers num=""/>
      </prod>
      <prod vendor="moodle" name="moodle">
        <vers num="1.5.3"/>
      </prod>
      <prod vendor="postnuke_software_foundation" name="postnuke">
        <vers num="0.761"/>
      </prod>
      <prod vendor="the_cacti_group" name="cacti">
        <vers num="0.8.6g"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0147" published="2006-01-09" name="CVE-2006-0147" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Dynamic code evaluation vulnerability in tests/tmssql.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PhpOpenChat, possibly (7) MAXdev MD-Pro, and (8) Simplog, allows remote attackers to execute arbitrary PHP functions via the do parameter, which is saved in a variable that is then executed as a function, as demonstrated using phpinfo.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.osvdb.org/22291" source="OSVDB" patch="1">22291</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-07.xml" source="GENTOO" patch="1" adv="1">GLSA-200604-07</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1030" source="DEBIAN" patch="1" adv="1">DSA-1030</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1029" source="DEBIAN" patch="1" adv="1">DSA-1029</ref>
      <ref url="http://secunia.com/secunia_research/2005-64/advisory/" source="MISC" patch="1" adv="1">http://secunia.com/secunia_research/2005-64/advisory/</ref>
      <ref url="http://secunia.com/advisories/19628" source="SECUNIA" patch="1" adv="1">19628</ref>
      <ref url="http://secunia.com/advisories/19591" source="SECUNIA" patch="1" adv="1">19591</ref>
      <ref url="http://secunia.com/advisories/19590" source="SECUNIA" patch="1" adv="1">19590</ref>
      <ref url="http://secunia.com/advisories/19555" source="SECUNIA" patch="1" adv="1">19555</ref>
      <ref url="http://secunia.com/advisories/18276" source="SECUNIA" patch="1" adv="1">18276</ref>
      <ref url="http://secunia.com/advisories/18260" source="SECUNIA" patch="1" adv="1">18260</ref>
      <ref url="http://secunia.com/advisories/18254" source="SECUNIA" patch="1" adv="1">18254</ref>
      <ref url="http://secunia.com/advisories/18233" source="SECUNIA" patch="1" adv="1">18233</ref>
      <ref url="http://secunia.com/advisories/17418" source="SECUNIA" patch="1" adv="1">17418</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1332" source="VUPEN">ADV-2006-1332</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1305" source="VUPEN">ADV-2006-1305</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0104" source="VUPEN">ADV-2006-0104</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0103" source="VUPEN">ADV-2006-0103</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0102" source="VUPEN">ADV-2006-0102</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0101" source="VUPEN">ADV-2006-0101</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430743/100/0/threaded" source="BUGTRAQ">20060412 Simplog &lt;=0.9.2 multiple vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430448/100/0/threaded" source="BUGTRAQ">20060409 PhpOpenChat 3.0.x ADODB Server.php "sql" SQL injection</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1031" source="DEBIAN">DSA-1031</ref>
      <ref url="http://secunia.com/advisories/19600" source="SECUNIA" adv="1">19600</ref>
      <ref url="http://secunia.com/advisories/18267" source="SECUNIA" adv="1">18267</ref>
      <ref url="http://retrogod.altervista.org/simplog_092_incl_xpl.html" source="MISC">http://retrogod.altervista.org/simplog_092_incl_xpl.html</ref>
      <ref url="http://retrogod.altervista.org/phpopenchat_30x_sql_xpl.html" source="MISC">http://retrogod.altervista.org/phpopenchat_30x_sql_xpl.html</ref>
      <ref url="http://milw0rm.com/exploits/1663" source="MILW0RM">1663</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24052" source="XF">adodb-tmssql-command-execution(24052)</ref>
      <ref url="http://secunia.com/advisories/19691" source="SECUNIA">19691</ref>
    </refs>
    <vuln_soft>
      <prod vendor="john_lim" name="adodb">
        <vers num="4.66"/>
        <vers num="4.68"/>
      </prod>
      <prod vendor="mantis" name="mantis">
        <vers num="0.19.4"/>
        <vers num="1.0.0_rc4"/>
      </prod>
      <prod vendor="moodle" name="moodle">
        <vers num="1.5.3"/>
      </prod>
      <prod vendor="postnuke_software_foundation" name="postnuke">
        <vers num="0.761"/>
      </prod>
      <prod vendor="the_cacti_group" name="cacti">
        <vers num="0.8.6g"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0148" published="2006-01-09" name="CVE-2006-0148" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">NetSarang Xlpd 2.1 allows remote attackers to cause a denial of service (crash) via a large number of connections from the same IP address.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16164" source="BID">16164</ref>
      <ref url="http://www.ipomonis.com/advisories/xlpd.txt" source="MISC" adv="1">http://www.ipomonis.com/advisories/xlpd.txt</ref>
      <ref url="http://securitytracker.com/id?1015444" source="SECTRACK">1015444</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24041" source="XF">xlpd-connection-dos(24041)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netsarang" name="xlpd">
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0149" published="2006-01-09" name="CVE-2006-0149" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in SimpBook 1.0, with html_enable on (the default), allows remote attackers to inject arbitrary web script or HTML via the message field.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1015451" source="SECTRACK" adv="1">1015451</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041127.html" source="FULLDISC" adv="1">20060106 SimpBook "message" Remote Cross-Site Scripting Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="simpbook" name="simpbook">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0150" published="2006-01-09" name="CVE-2006-0150" modified="2011-09-09" discovered="2005-12-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple format string vulnerabilities in the auth_ldap_log_reason function in Apache auth_ldap 1.6.0 and earlier allows remote attackers to execute arbitrary code via various vectors, including the username.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:017" source="MANDRIVA" patch="1" adv="1">MDKSA-2006:017</ref>
      <ref url="http://www.securityfocus.com/bid/16177" source="BID" patch="1">16177</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0179.html" source="REDHAT" patch="1" adv="1">RHSA-2006:0179</ref>
      <ref url="http://www.debian.org/security/2006/dsa-952" source="DEBIAN" patch="1" adv="1">DSA-952</ref>
      <ref url="http://secunia.com/advisories/18568" source="SECUNIA" patch="1" adv="1">18568</ref>
      <ref url="http://secunia.com/advisories/18412" source="SECUNIA" patch="1" adv="1">18412</ref>
      <ref url="http://secunia.com/advisories/18405" source="SECUNIA" patch="1" adv="1">18405</ref>
      <ref url="http://secunia.com/advisories/18382" source="SECUNIA" patch="1" adv="1">18382</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24030" source="XF">apache-authldap-format-string(24030)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0117" source="VUPEN" adv="1">ADV-2006-0117</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421286/100/0/threaded" source="BUGTRAQ" adv="1">20060109 Digital Armaments Security Advisory 01.09.2006: Apache auth_ldap module Multiple Format Strings Vulnerability</ref>
      <ref url="http://www.rudedog.org/auth_ldap/Changes.html" source="CONFIRM">http://www.rudedog.org/auth_ldap/Changes.html</ref>
      <ref url="http://www.digitalarmaments.com/2006090173928420.html" source="MISC" adv="1">http://www.digitalarmaments.com/2006090173928420.html</ref>
      <ref url="http://securitytracker.com/id?1015456" source="SECTRACK">1015456</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dave_carrigan" name="auth_ldap">
        <vers num="1.2.1"/>
        <vers num="1.2.2"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.3.0"/>
        <vers num="1.3.1"/>
        <vers num="1.3.2"/>
        <vers num="1.3.3"/>
        <vers num="1.3.4"/>
        <vers num="1.4.0"/>
        <vers num="1.4.2"/>
        <vers num="1.4.3"/>
        <vers num="1.6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0151" published="2006-01-09" name="CVE-2006-0151" modified="2010-04-02" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">sudo 1.6.8 and other versions does not clear the PYTHONINSPECT environment variable, which allows limited local users to gain privileges via a Python script, a variant of CVE-2005-4158.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <design/>
      <env/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18363" source="SECUNIA" patch="1" adv="1">18363</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-235-2" source="UBUNTU">USN-235-2</ref>
      <ref url="http://www.securityfocus.com/bid/16184" source="BID">16184</ref>
      <ref url="http://secunia.com/advisories/18358" source="SECUNIA" adv="1">18358</ref>
      <ref url="http://www.trustix.org/errata/2006/0010" source="TRUSTIX">2006-0010</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_02_sr.html" source="SUSE">SUSE-SR:2006:002</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:159" source="MANDRIVA">MDKSA-2006:159</ref>
      <ref url="http://www.debian.org/security/2006/dsa-946" source="DEBIAN">DSA-946</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.421822" source="SLACKWARE">SSA:2006-045-08</ref>
      <ref url="http://secunia.com/advisories/21692" source="SECUNIA">21692</ref>
      <ref url="http://secunia.com/advisories/19016" source="SECUNIA">19016</ref>
      <ref url="http://secunia.com/advisories/18906" source="SECUNIA">18906</ref>
      <ref url="http://secunia.com/advisories/18558" source="SECUNIA">18558</ref>
      <ref url="http://secunia.com/advisories/18549" source="SECUNIA">18549</ref>
    </refs>
    <vuln_soft>
      <prod vendor="todd_miller" name="sudo">
        <vers num="1.5.6"/>
        <vers num="1.5.7"/>
        <vers num="1.5.8"/>
        <vers num="1.5.9"/>
        <vers num="1.6"/>
        <vers num="1.6.1"/>
        <vers num="1.6.2"/>
        <vers num="1.6.3"/>
        <vers num="1.6.3_p1"/>
        <vers num="1.6.3_p2"/>
        <vers num="1.6.3_p3"/>
        <vers num="1.6.3_p4"/>
        <vers num="1.6.3_p5"/>
        <vers num="1.6.3_p6"/>
        <vers num="1.6.3_p7"/>
        <vers num="1.6.4"/>
        <vers num="1.6.4_p1"/>
        <vers num="1.6.4_p2"/>
        <vers num="1.6.5"/>
        <vers num="1.6.5_p1"/>
        <vers num="1.6.5_p2"/>
        <vers num="1.6.6"/>
        <vers num="1.6.7"/>
        <vers num="1.6.7_p5"/>
        <vers num="1.6.8"/>
        <vers num="1.6.8_p1"/>
        <vers num="1.6.8_p12"/>
        <vers num="1.6.8_p2"/>
        <vers num="1.6.8_p5"/>
        <vers num="1.6.8_p7"/>
        <vers num="1.6.8_p8"/>
        <vers num="1.6.8_p9"/>
      </prod>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="4.1" edition=""/>
        <vers num="4.1" edition=":ia64"/>
        <vers num="4.1" edition=":ppc"/>
        <vers num="5.04" edition=""/>
        <vers num="5.04" edition=":i386"/>
        <vers num="5.04" edition=":amd64"/>
        <vers num="5.04" edition=":powerpc"/>
        <vers num="5.10" edition=""/>
        <vers num="5.10" edition=":powerpc"/>
        <vers num="5.10" edition=":i386"/>
        <vers num="5.10" edition=":amd64"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0152" published="2006-01-10" name="CVE-2006-0152" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) in search_result.php in phpChamber 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the needle parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0094" source="VUPEN">ADV-2006-0094</ref>
      <ref url="http://www.securityfocus.com/bid/16180" source="BID">16180</ref>
      <ref url="http://secunia.com/advisories/18360" source="SECUNIA" adv="1">18360</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24029" source="XF">phpchamber-searchresult-xss(24029)</ref>
      <ref url="http://www.osvdb.org/22282" source="OSVDB">22282</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpchamber" name="phpchamber">
        <vers prev="1" num="1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0153" published="2006-01-10" name="CVE-2006-0153" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">427BB 2.2 and 2.2.1 verifies authentication credentials based on the username, authenticated, and usertype cookies, which allows remote attackers to bypass authentication by using a valid username and usertype and setting the authenticated cookie.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0091" source="VUPEN">ADV-2006-0091</ref>
      <ref url="http://www.securityfocus.com/bid/16178" source="BID">16178</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421326/100/0/threaded" source="BUGTRAQ" adv="1">20060107 [eVuln] 427BB Multiple Vulnerabilities (Cookie-based Authentication Bypass, SQL Injections, XSS)</ref>
      <ref url="http://secunia.com/advisories/18354" source="SECUNIA" adv="1">18354</ref>
      <ref url="http://evuln.com/vulns/18/summary.html" source="MISC" adv="1">http://evuln.com/vulns/18/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24038" source="XF">427bb-scripts-security-bypass(24038)</ref>
      <ref url="http://www.osvdb.org/22274" source="OSVDB">22274</ref>
    </refs>
    <vuln_soft>
      <prod vendor="427bb" name="fourtwosevenbb">
        <vers num="2.2"/>
        <vers num="2.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0154" published="2006-01-10" name="CVE-2006-0154" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in showthread.php in 427BB 2.2 and 2.2.1 allows remote attackers to execute arbitrary SQL commands via the ForumID parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0091" source="VUPEN">ADV-2006-0091</ref>
      <ref url="http://www.securityfocus.com/bid/16169" source="BID">16169</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421326/100/0/threaded" source="BUGTRAQ" adv="1">20060107 [eVuln] 427BB Multiple Vulnerabilities (Cookie-based Authentication Bypass, SQL Injections, XSS)</ref>
      <ref url="http://secunia.com/advisories/18354" source="SECUNIA" adv="1">18354</ref>
      <ref url="http://evuln.com/vulns/18/summary.html" source="MISC" adv="1">http://evuln.com/vulns/18/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24039" source="XF">427bb-showthread-sql-injection(24039)</ref>
      <ref url="http://www.osvdb.org/22275" source="OSVDB">22275</ref>
    </refs>
    <vuln_soft>
      <prod vendor="427bb" name="fourtwosevenbb">
        <vers num="2.2"/>
        <vers num="2.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0155" published="2006-01-10" name="CVE-2006-0155" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in posts.php in 427BB 2.2 and 2.2.1 allows remote attackers to inject arbitrary Javascript via a new message with a url bbcode tag containing a javascript URI.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0091" source="VUPEN">ADV-2006-0091</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421326/100/0/threaded" source="BUGTRAQ" adv="1">20060107 [eVuln] 427BB Multiple Vulnerabilities (Cookie-based Authentication Bypass, SQL Injections, XSS)</ref>
      <ref url="http://secunia.com/advisories/18354" source="SECUNIA" adv="1">18354</ref>
      <ref url="http://evuln.com/vulns/18/summary.html" source="MISC">http://evuln.com/vulns/18/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24040" source="XF">427bb-posts-xss(24040)</ref>
      <ref url="http://www.osvdb.org/22276" source="OSVDB">22276</ref>
    </refs>
    <vuln_soft>
      <prod vendor="427bb" name="fourtwosevenbb">
        <vers num="2.2"/>
        <vers num="2.2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0156" published="2006-01-10" name="CVE-2006-0156" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Foxrum 4.0.4f allows remote attackers to inject arbitrary Javascript via the javascript URI in bbcode url tags in (1) addpost1.php and (2) addtopic1.php.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0121" source="VUPEN">ADV-2006-0121</ref>
      <ref url="http://www.securityfocus.com/bid/16172" source="BID">16172</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421277/100/0/threaded" source="BUGTRAQ" adv="1">20060109 [eVuln] Foxrum BBCode XSS Vulnerabilty</ref>
      <ref url="http://secunia.com/advisories/18386" source="SECUNIA" adv="1">18386</ref>
      <ref url="http://evuln.com/vulns/20" source="MISC" adv="1">http://evuln.com/vulns/20</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24043" source="XF">foxrum-bbcode-xss(24043)</ref>
      <ref url="http://securityreason.com/securityalert/325" source="SREASON">325</ref>
    </refs>
    <vuln_soft>
      <prod vendor="foxrum" name="foxrum">
        <vers num="4.0.4f"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0157" published="2006-01-10" name="CVE-2006-0157" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">settings.php in Reamday Enterprises Magic News Plus 1.0.3 allows remote attackers to change the administrator password via a change action that specifies identical values for the passwd and admin_password parameters, then declares the new password string in the new_passwd and confirm_passwd parameters.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16182" source="BID">16182</ref>
      <ref url="http://downloads.securityfocus.com/vulnerabilities/exploits/MagicNewsPlus-pw-change.pl" source="MISC">http://downloads.securityfocus.com/vulnerabilities/exploits/MagicNewsPlus-pw-change.pl</ref>
      <ref url="http://secunia.com/advisories/18601" source="SECUNIA">18601</ref>
    </refs>
    <vuln_soft>
      <prod vendor="reamday_enterprises" name="magic_news_plus">
        <vers num="1.0.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0158" published="2006-01-10" name="CVE-2006-0158" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in CyberDoc SiteSuite CMS allows remote attackers to execute arbitrary SQL commands via the page parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0038" source="VUPEN">ADV-2006-0038</ref>
      <ref url="http://www.osvdb.org/22205" source="OSVDB">22205</ref>
      <ref url="http://secunia.com/advisories/18305" source="SECUNIA" adv="1">18305</ref>
      <ref url="http://osvdb.org/ref/22/22205-sitesuite.txt" source="MISC">http://osvdb.org/ref/22/22205-sitesuite.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cyberdoc" name="sitesuite_cms">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0159" published="2006-01-10" name="CVE-2006-0159" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in escribir.php in Foro Domus 2.10 allows remote attackers to execute arbitrary SQL commands via the email parameter.  NOTE: the provenance of this information is unknown, although it may be based on post-disclosure analysis of CVE-2006-0110; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24017" source="XF">domus-escribir-sql-injection(24017)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0073" source="VUPEN">ADV-2006-0073</ref>
      <ref url="http://www.osvdb.org/22264" source="OSVDB">22264</ref>
      <ref url="http://secunia.com/advisories/18327" source="SECUNIA" adv="1">18327</ref>
    </refs>
    <vuln_soft>
      <prod vendor="javier_suarez_sanz" name="foro_domus">
        <vers num="2.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0160" published="2006-01-10" name="CVE-2006-0160" modified="2011-08-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in add_post.php3 in Venom Board 1.22 allows remote attackers to execute arbitrary SQL commands via the (1) parent, (2) root, and (3) topic_id parameters to post.php3.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24046" source="XF">venomboard-addpost-sql-injection(24046)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0122" source="VUPEN" adv="1">ADV-2006-0122</ref>
      <ref url="http://www.securityfocus.com/bid/16176" source="BID">16176</ref>
      <ref url="http://www.osvdb.org/22297" source="OSVDB">22297</ref>
      <ref url="http://securityreason.com/securityalert/326" source="SREASON">326</ref>
      <ref url="http://secunia.com/advisories/18383" source="SECUNIA" adv="1">18383</ref>
      <ref url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=113683807903915&amp;w=2" source="BUGTRAQ" adv="1">20060109 [eVuln] Venom Board SQL Injection Vulnerability</ref>
      <ref url="http://evuln.com/vulns/21/summary.html" source="MISC" adv="1">http://evuln.com/vulns/21/summary.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="venom_board" name="venom_board">
        <vers num="1.22"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0161" published="2006-01-10" name="CVE-2006-0161" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Unspecified vulnerability in uucp in Sun Solaris 8 and 9 has unknown impact and attack vectors.  NOTE: due to the vagueness of the vendor advisory, it is not clear whether this is related to CVE-2004-0780.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101933-1" source="SUNALERT" patch="1" adv="1">101933</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0113" source="VUPEN">ADV-2006-0113</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-056.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-056.htm</ref>
      <ref url="http://securitytracker.com/id?1015455" source="SECTRACK">1015455</ref>
      <ref url="http://secunia.com/advisories/19087" source="SECUNIA">19087</ref>
      <ref url="http://secunia.com/advisories/18371" source="SECUNIA">18371</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1534" source="OVAL" sig="1">oval:org.mitre.oval:def:1534</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="8.0"/>
        <vers num="9.0" edition=""/>
        <vers num="9.0" edition=":sparc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0162" published="2006-01-10" name="CVE-2006-0162" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in libclamav/upx.c in Clam Antivirus (ClamAV) before 0.88 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted UPX files.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/385908" source="CERT-VN">VU#385908</ref>
      <ref url="http://www.securityfocus.com/bid/16191" source="BID" patch="1">16191</ref>
      <ref url="http://secunia.com/advisories/18379" source="SECUNIA" patch="1" adv="1">18379</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0116" source="VUPEN">ADV-2006-0116</ref>
      <ref url="http://www.clamav.net/doc/0.88/ChangeLog" source="CONFIRM">http://www.clamav.net/doc/0.88/ChangeLog</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24047" source="XF">clamav-libclamav-upx-bo(24047)</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-06-001.html" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-06-001.html</ref>
      <ref url="http://www.trustix.org/errata/2006/0002/" source="TRUSTIX">2006-0002</ref>
      <ref url="http://www.osvdb.org/22318" source="OSVDB">22318</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:016" source="MANDRIVA">MDKSA-2006:016</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200601-07.xml" source="GENTOO">GLSA-200601-07</ref>
      <ref url="http://www.debian.org/security/2006/dsa-947" source="DEBIAN">DSA-947</ref>
      <ref url="http://securitytracker.com/id?1015457" source="SECTRACK">1015457</ref>
      <ref url="http://securityreason.com/securityalert/342" source="SREASON">342</ref>
      <ref url="http://secunia.com/advisories/18548" source="SECUNIA">18548</ref>
      <ref url="http://secunia.com/advisories/18478" source="SECUNIA">18478</ref>
      <ref url="http://secunia.com/advisories/18463" source="SECUNIA">18463</ref>
      <ref url="http://secunia.com/advisories/18453" source="SECUNIA">18453</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041325.html" source="FULLDISC">20060112 ZDI-06-001: Clam AntiVirus UPX Unpacking Code Execution Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clam_anti-virus" name="clamav">
        <vers num="."/>
        <vers num="0.51"/>
        <vers num="0.52"/>
        <vers num="0.53"/>
        <vers num="0.54"/>
        <vers num="0.60"/>
        <vers num="0.65"/>
        <vers num="0.67"/>
        <vers num="0.68"/>
        <vers num="0.68.1"/>
        <vers num="0.70"/>
        <vers num="0.75.1"/>
        <vers num="0.80"/>
        <vers num="0.80_rc1"/>
        <vers num="0.80_rc2"/>
        <vers num="0.80_rc3"/>
        <vers num="0.80_rc4"/>
        <vers num="0.81"/>
        <vers num="0.82"/>
        <vers num="0.83"/>
        <vers num="0.84"/>
        <vers num="0.84_rc1"/>
        <vers num="0.84_rc2"/>
        <vers num="0.85"/>
        <vers num="0.85.1"/>
        <vers num="0.86"/>
        <vers num="0.86.1"/>
        <vers num="0.86.2"/>
        <vers num="0.87"/>
        <vers num="0.87.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0163" published="2006-01-11" name="CVE-2006-0163" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the search module (modules/Search/index.php) of PHPNuke EV 7.7 -R1 allows remote attackers to execute arbitrary SQL commands via the query parameter, which is used by the search field.  NOTE: This is a different vulnerability than CVE-2005-3792.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/44978" source="XF">phpnukeev-search-sql-injection(44978)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0120" source="VUPEN">ADV-2006-0120</ref>
      <ref url="http://www.securityfocus.com/bid/16186" source="BID">16186</ref>
      <ref url="http://www.osvdb.org/22316" source="OSVDB">22316</ref>
      <ref url="http://secunia.com/advisories/18394" source="SECUNIA">18394</ref>
      <ref url="http://lostmon.blogspot.com/2006/01/phpnuke-ev-77-search-module-query.html" source="MISC" adv="1">http://lostmon.blogspot.com/2006/01/phpnuke-ev-77-search-module-query.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francisco_burzi" name="php-nuke_ev">
        <vers num="7.7_r1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0164" published="2006-01-11" name="CVE-2006-0164" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">phgstats.inc.php in phgstats before 0.5.1, if register_globals is enabled, allows remote attackers to include arbitrary files and execute arbitrary PHP code by modifying the PHGDIR variable.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=384232" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=384232</ref>
      <ref url="http://secunia.com/advisories/18346" source="SECUNIA" patch="1" adv="1">18346</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0123" source="VUPEN">ADV-2006-0123</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24062" source="XF">phgstats-php-file-include(24062)</ref>
      <ref url="http://www.securityfocus.com/bid/17469" source="BID">17469</ref>
      <ref url="http://www.osvdb.org/22302" source="OSVDB">22302</ref>
    </refs>
    <vuln_soft>
      <prod vendor="woah-projekt" name="phgstats">
        <vers num="0.1"/>
        <vers num="0.2"/>
        <vers num="0.3"/>
        <vers num="0.3.1"/>
        <vers num="0.4"/>
        <vers num="0.4.1"/>
        <vers num="0.4.2"/>
        <vers num="0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0165" published="2006-01-11" name="CVE-2006-0165" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the DataForm Entries functionality in Plain Black WebGUI before 6.8.4 (gamma) allows remote attackers to inject arbitrary Javascript via the (1) url and (2) name field of the default email form.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=384153&amp;group_id=51417" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=384153&amp;group_id=51417</ref>
      <ref url="http://secunia.com/advisories/18372" source="SECUNIA" patch="1" adv="1">18372</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0126" source="VUPEN">ADV-2006-0126</ref>
      <ref url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1395371&amp;group_id=51417&amp;atid=463213" source="MISC">http://sourceforge.net/tracker/index.php?func=detail&amp;aid=1395371&amp;group_id=51417&amp;atid=463213</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24053" source="XF">webgui-forms-xss(24053)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="plain_black" name="webgui">
        <vers num="5.5.8"/>
        <vers num="6.2.10_gamma"/>
        <vers num="6.2.11_gamma"/>
        <vers num="6.3.0_beta"/>
        <vers num="6.4.0_beta"/>
        <vers num="6.5.0_beta"/>
        <vers num="6.5.1_beta"/>
        <vers num="6.5.2_beta"/>
        <vers num="6.5.3_beta"/>
        <vers num="6.5.4_gamma"/>
        <vers num="6.5.5_gamma"/>
        <vers num="6.5.6_gamma"/>
        <vers num="6.6.0_beta"/>
        <vers num="6.6.1_beta"/>
        <vers num="6.6.2_gamma"/>
        <vers num="6.6.3_gamma"/>
        <vers num="6.6.4_gamma"/>
        <vers num="6.6.5"/>
        <vers num="6.7.0_beta"/>
        <vers num="6.7.1_beta"/>
        <vers num="6.7.2_beta"/>
        <vers num="6.7.3_gamma"/>
        <vers num="6.7.4_gamma"/>
        <vers num="6.7.5_gamma"/>
        <vers num="6.7.6_gamma"/>
        <vers num="6.7.7_gamma"/>
        <vers num="6.7.8_gamma"/>
        <vers num="6.8.1_beta"/>
        <vers num="6.8.2_beta"/>
        <vers num="6.8.3_gamma"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0166" published="2006-01-11" name="CVE-2006-0166" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Symantec Norton SystemWorks and SystemWorks Premier 2005 and 2006 stores temporary copies of files in the Norton Protected Recycle Bin NProtect directory, which is hidden from the FindFirst and FindNext Windows APIs and allows remote attackers to hide arbitrary files from virus scanners and other products.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1015462" source="SECTRACK" patch="1">1015462</ref>
      <ref url="http://securityresponse.symantec.com/avcenter/security/Content/2006.01.10.html" source="CONFIRM" patch="1" adv="1">http://securityresponse.symantec.com/avcenter/security/Content/2006.01.10.html</ref>
      <ref url="http://secunia.com/advisories/18402" source="SECUNIA" patch="1" adv="1">18402</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24061" source="XF">systemworks-nprotect-hidden(24061)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0143" source="VUPEN">ADV-2006-0143</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="norton_system_works">
        <vers num="2005"/>
        <vers num="2005_premier"/>
        <vers num="2006"/>
        <vers num="2006_premier"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0167" published="2006-01-11" name="CVE-2006-0167" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in MyPhPim 01.05 allows remote attackers to execute arbitrary SQL commands via the (1) cal_id parameter in calendar.php3 and the (2) password field on the login page.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24075" source="XF">myphpim-login-sql-injection(24075)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24066" source="XF">myphpim-calendar-sql-injection(24066)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0147" source="VUPEN">ADV-2006-0147</ref>
      <ref url="http://www.securityfocus.com/bid/16210" source="BID">16210</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421863/100/0/threaded" source="BUGTRAQ">20060111 [eVuln] MyPhPim Multiple SQL Injection and XSS Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/22325" source="OSVDB">22325</ref>
      <ref url="http://www.osvdb.org/22324" source="OSVDB">22324</ref>
      <ref url="http://secunia.com/advisories/18399" source="SECUNIA" adv="1">18399</ref>
      <ref url="http://evuln.com/vulns/22/summary.html" source="MISC" adv="1">http://evuln.com/vulns/22/summary.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="myphpim" name="myphpim">
        <vers num="01.05"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0168" published="2006-01-11" name="CVE-2006-0168" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in MyPhPim 01.05 allows remote attackers to inject arbitrary web script or HTML via the description field on the "Create New todo" page.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24071" source="XF">myphpim-todo-xss(24071)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0147" source="VUPEN">ADV-2006-0147</ref>
      <ref url="http://www.securityfocus.com/bid/16210" source="BID">16210</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421863/100/0/threaded" source="BUGTRAQ">20060111 [eVuln] MyPhPim Multiple SQL Injection and XSS Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/22326" source="OSVDB">22326</ref>
      <ref url="http://secunia.com/advisories/18399" source="SECUNIA" adv="1">18399</ref>
      <ref url="http://evuln.com/vulns/22/summary.html" source="MISC" adv="1">http://evuln.com/vulns/22/summary.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="myphpim" name="myphpim">
        <vers num="01.05"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0169" published="2006-01-11" name="CVE-2006-0169" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">addresses.php3 in MyPhPim 01.05 does not restrict uploaded files, which allows remote attackers to execute arbitrary PHP code via the pdbfile variable, then directly accessing those files from the uploads directory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24070" source="XF">myphpim-addresses-file-upload(24070)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0147" source="VUPEN">ADV-2006-0147</ref>
      <ref url="http://www.securityfocus.com/bid/16208" source="BID">16208</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421626/100/0/threaded" source="BUGTRAQ" adv="1">20060111 [eVuln] MyPhPim Arbitrary File Upload</ref>
      <ref url="http://secunia.com/advisories/18399" source="SECUNIA" adv="1">18399</ref>
      <ref url="http://evuln.com/vulns/23/summary.html" source="MISC">http://evuln.com/vulns/23/summary.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="myphpim" name="myphpim">
        <vers num="01.05"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2006-0170" reject="1" published="2006-01-11" name="CVE-2006-0170" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2006-0035.  Reason: This candidate is a duplicate of CVE-2006-0035.  Notes: All CVE users should reference CVE-2006-0035 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0171" published="2006-01-11" name="CVE-2006-0171" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file include vulnerability in index.php in OrjinWeb E-commerce allows remote attackers to execute arbitrary code via a URL in the page parameter.  NOTE: it is not clear, but OrjinWeb might be an application service, in which case it should not be included in CVE.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16199" source="BID">16199</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421312/100/0/threaded" source="BUGTRAQ">20060106 Orjinweb E-commerce</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24097" source="XF">orjinweb-url-file-include(24097)</ref>
      <ref url="http://www.osvdb.org/22387" source="OSVDB">22387</ref>
    </refs>
    <vuln_soft>
      <prod vendor="orjinweb" name="orjinweb_e-commerce">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0172" published="2006-01-11" name="CVE-2006-0172" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the file manager utility in Hummingbird Collaboration (aka Hummingbird Enterprise Collaboration) 5.21 and earlier allows remote attackers to inject arbitrary web script or HTML in an uploaded page, which is published without a check for hostile scripting.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0145" source="VUPEN">ADV-2006-0145</ref>
      <ref url="http://www.securityfocus.com/bid/16195" source="BID">16195</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421392/100/0/threaded" source="BUGTRAQ" adv="1">20060110 Multiple Vulnerabilities in Hummingbird Collaboration</ref>
      <ref url="http://www.securenetwork.it/advisories/sn-2006-01.html" source="MISC" adv="1">http://www.securenetwork.it/advisories/sn-2006-01.html</ref>
      <ref url="http://secunia.com/advisories/18411" source="SECUNIA" adv="1">18411</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24067" source="XF">hummingbird-enterprise-xss(24067)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hummingbird" name="enterprise_collaboration">
        <vers num="5.2"/>
        <vers prev="1" num="5.21"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0173" published="2006-01-11" name="CVE-2006-0173" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Hummingbird Collaboration (aka Hummingbird Enterprise Collaboration) 5.21 and earlier allows remote attackers to misrepresent the type and name of a file via modified doc_ext and id parameters, which might trick a user into downloading dangerous or unexpected content.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0145" source="VUPEN">ADV-2006-0145</ref>
      <ref url="http://www.securityfocus.com/bid/16195" source="BID">16195</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421392/100/0/threaded" source="BUGTRAQ" adv="1">20060110 Multiple Vulnerabilities in Hummingbird Collaboration</ref>
      <ref url="http://www.securenetwork.it/advisories/sn-2006-01.html" source="MISC" adv="1">http://www.securenetwork.it/advisories/sn-2006-01.html</ref>
      <ref url="http://secunia.com/advisories/18411" source="SECUNIA" adv="1">18411</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24068" source="XF">hummingbird-enterprise-file-download(24068)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hummingbird" name="enterprise_collaboration">
        <vers num="5.2"/>
        <vers prev="1" num="5.21"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0174" published="2006-01-11" name="CVE-2006-0174" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Hummingbird Collaboration (aka Hummingbird Enterprise Collaboration) 5.21 and earlier allows remote attackers to obtain sensitive information (intranet IP addresses and enumerations of valid parameter values) via a direct request to hc, which reveals the information in an error message or a cookie.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0145" source="VUPEN">ADV-2006-0145</ref>
      <ref url="http://www.securityfocus.com/bid/16195" source="BID">16195</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421392/100/0/threaded" source="BUGTRAQ">20060110 Multiple Vulnerabilities in Hummingbird Collaboration</ref>
      <ref url="http://www.securenetwork.it/advisories/sn-2006-01.html" source="MISC">http://www.securenetwork.it/advisories/sn-2006-01.html</ref>
      <ref url="http://secunia.com/advisories/18411" source="SECUNIA">18411</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24069" source="XF">hummingbird-enterprise-information-disclosure(24069)</ref>
      <ref url="http://securityreason.com/securityalert/328" source="SREASON">328</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hummingbird" name="collaboration">
        <vers num="5.2"/>
        <vers prev="1" num="5.21"/>
      </prod>
      <prod vendor="hummingbird" name="enterprise_collaboration">
        <vers num="5.2"/>
        <vers prev="1" num="5.21"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0175" published="2006-01-11" name="CVE-2006-0175" modified="2013-01-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in search_form.asp in Web Wiz Forums 6.34 allows remote attackers to inject arbitrary web script or HTML via the search parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16196" source="BID" patch="1">16196</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24048" source="XF">webwizforums-searchform-xss(24048)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421615/100/0/threaded" source="BUGTRAQ">20060111 Advisory:XSS vulnerability on WebWiz Forums &lt;= 6.34(search_form.asp)</ref>
      <ref url="http://www.osvdb.org/22398" source="OSVDB">22398</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0299.html" source="FULLDISC">20060109 Advisory:XSS vulnerability on WebWiz Forums &lt;= 6.34 (search_form.asp)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webwiz" name="web_wiz_forums">
        <vers num="6.34"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0176" published="2006-01-11" name="CVE-2006-0176" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in certain functions in src/fileio.c and src/unix/fileio.c in xmame before 11 January 2006 may allow local users to gain privileges via a long (1) -lang, (2) -ctrlr, (3) -pb, or (4) -rec argument on many operating systems, and via a long (5) -jdev argument on Ubuntu Linux.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16203" source="BID">16203</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421849/100/0/threaded" source="BUGTRAQ">20060110 mysec.org Security Advisory : Xmame buffer overflow, with a possibility of privilege escalation</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0353.html" source="FULLDISC">20060110 mysec.org Security Advisory : Xmame buffer overflow, with a possibility of privilege escalation.</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24102" source="XF">xmame-multiple-parameters-bo(24102)</ref>
      <ref url="http://x.mame.net/changes-unix.html" source="CONFIRM">http://x.mame.net/changes-unix.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xmame" name="xmame">
        <vers num="0.102"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0177" published="2006-01-11" name="CVE-2006-0177" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Multiple buffer overflows in Cray UNICOS 9.0.2.2 might allow local users to gain privileges by (1) invoking /usr/bin/script with a long command line argument or (2) setting the -c option of /etc/nu to the name of a file containing a long line.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16205" source="BID">16205</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0343.html" source="FULLDISC">20060110 SUID root overflows in UNICOS and partial shellcode</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24276" source="XF">unicos-command-line-bo(24276)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cray" name="unicos">
        <vers num="9.0.2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0178" published="2006-01-11" name="CVE-2006-0178" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Format string vulnerability in /bin/ftp in UNICOS 9.0.2.2 allows local users to have an unknown impact via format string specifiers in the quote command.  NOTE: because the program is not setuid and not normally called from remote programs, there may not be a typical attack vector for the issue that crosses privilege boundaries. Therefore this may not be a vulnerability.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16205" source="BID">16205</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0343.html" source="FULLDISC">20060110 SUID root overflows in UNICOS and partial shellcode</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24277" source="XF">unicos-ftp-format-string(24277)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cray" name="unicos">
        <vers num="9.0.2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0179" published="2006-01-11" name="CVE-2006-0179" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Cisco IP Phone 7940 allows remote attackers to cause a denial of service (reboot) via a large amount of TCP SYN packets (syn flood) to arbitrary ports, as demonstrated to port 80.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1015488" source="SECTRACK" patch="1">1015488</ref>
      <ref url="http://secunia.com/advisories/18479" source="SECUNIA" patch="1" adv="1">18479</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24117" source="XF">cisco-ipphone-synflood-dos(24117)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0202" source="VUPEN" adv="1">ADV-2006-0202</ref>
      <ref url="http://www.securityfocus.com/bid/16200" source="BID">16200</ref>
      <ref url="http://www.osvdb.org/22469" source="OSVDB">22469</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-response-20060113-ip-phones.shtml" source="CISCO" adv="1">20060113 Response to Cisco IP Phone 7940 DoS Exploit posted on milw0rm.com</ref>
      <ref url="http://downloads.securityfocus.com/vulnerabilities/exploits/cisco_ip7940_dos.pl" source="MISC">http://downloads.securityfocus.com/vulnerabilities/exploits/cisco_ip7940_dos.pl</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ip_phone_7940">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0180" published="2006-01-12" name="CVE-2006-0180" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in CaLogic Calendars 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the Title field on the "Adding New Event" page, and possibly other vectors, involving iframe tags.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0149" source="VUPEN">ADV-2006-0149</ref>
      <ref url="http://www.securityfocus.com/bid/16206" source="BID">16206</ref>
      <ref url="http://secunia.com/advisories/18417" source="SECUNIA" adv="1">18417</ref>
      <ref url="http://evuln.com/vulns/24/summary.html" source="MISC" adv="1">http://evuln.com/vulns/24/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24077" source="XF">calogic-newevent-xss(24077)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422163/100/0/threaded" source="BUGTRAQ">20060116 [eVuln] CaLogic Calendars Multiple XSS Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/22322" source="OSVDB">22322</ref>
    </refs>
    <vuln_soft>
      <prod vendor="calogic" name="calogic_calendars">
        <vers num="1.2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0181" published="2006-01-12" name="CVE-2006-0181" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Cisco Security Monitoring, Analysis and Response System (CS-MARS) before 4.1.3 has an undocumented administrative account with a default password, which allows local users to gain privileges via the expert command.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16211" source="BID" patch="1">16211</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20060111-mars.shtml" source="CISCO" patch="1" adv="1">20060111 Default Administrative Password in Cisco Security Monitoring, Analysis and Response System (CS-MARS)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0154" source="VUPEN">ADV-2006-0154</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24065" source="XF">cisco-csmars-default-password(24065)</ref>
      <ref url="http://www.osvdb.org/22346" source="OSVDB">22346</ref>
      <ref url="http://securitytracker.com/id?1015471" source="SECTRACK">1015471</ref>
      <ref url="http://securityreason.com/securityalert/335" source="SREASON">335</ref>
      <ref url="http://secunia.com/advisories/18424" source="SECUNIA">18424</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="cs-mars">
        <vers num="4.1"/>
        <vers num="4.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0182" published="2006-01-12" name="CVE-2006-0182" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">login.php in ACal Calendar Project 2.2.5 allows remote attackers to bypass authentication by setting the ACalAuthenticate cookie variable to "inside".</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0152" source="VUPEN">ADV-2006-0152</ref>
      <ref url="http://evuln.com/vulns/25/summary.html" source="MISC" adv="1">http://evuln.com/vulns/25/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24104" source="XF">acal-login-auth-bypass(24104)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421744/100/0/threaded" source="BUGTRAQ">20060112 [eVuln] ACal Authentication Bypass &amp; PHP Code Insertion</ref>
      <ref url="http://www.osvdb.org/22344" source="OSVDB">22344</ref>
      <ref url="http://securityreason.com/securityalert/343" source="SREASON">343</ref>
      <ref url="http://secunia.com/advisories/18432" source="SECUNIA">18432</ref>
    </refs>
    <vuln_soft>
      <prod vendor="acal" name="calendar_project">
        <vers num="2.2.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0183" published="2006-01-12" name="CVE-2006-0183" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Direct static code injection vulnerability in edit.php in ACal Calendar Project 2.2.5 allows authenticated users to execute arbitrary PHP code via (1) the edit=header value, which modifies header.php, or (2) the edit=footer value, which modifies footer.php.  NOTE: this issue might be resultant from the poor authentication as identified by CVE-2006-0182.  Since the design of the product allows the administrator to edit the code, perhaps this issue should not be included in CVE, except as a consequence of CVE-2006-0182.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0152" source="VUPEN">ADV-2006-0152</ref>
      <ref url="http://evuln.com/vulns/25/summary.html" source="MISC" adv="1">http://evuln.com/vulns/25/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24107" source="XF">acal-header-footer-code-execute(24107)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421744/100/0/threaded" source="BUGTRAQ">20060112 [eVuln] ACal Authentication Bypass &amp; PHP Code Insertion</ref>
      <ref url="http://www.osvdb.org/22345" source="OSVDB">22345</ref>
      <ref url="http://securityreason.com/securityalert/343" source="SREASON">343</ref>
      <ref url="http://secunia.com/advisories/18432" source="SECUNIA">18432</ref>
    </refs>
    <vuln_soft>
      <prod vendor="acal" name="calendar_project">
        <vers num="2.2.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0184" published="2006-01-12" name="CVE-2006-0184" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in AspTopSites allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to goto.asp or (2) password parameter to includeloginuser.asp.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0146" source="VUPEN">ADV-2006-0146</ref>
      <ref url="http://www.exploitlabs.com/files/advisories/EXPL-A-2006-001-asptopsites.txt" source="MISC" adv="1">http://www.exploitlabs.com/files/advisories/EXPL-A-2006-001-asptopsites.txt</ref>
      <ref url="http://secunia.com/advisories/18408" source="SECUNIA" adv="1">18408</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24072" source="XF">asptopsites-goto-sql-injection(24072)</ref>
      <ref url="http://www.osvdb.org/22330" source="OSVDB">22330</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0351.html" source="FULLDISC">20060110 AspTopSites SQL injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mainenet_enterprises" name="asptopsites">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0185" published="2006-01-12" name="CVE-2006-0185" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple cross-site scripting vulnerabilities in the (1) Pool or (2) News Modules in Php-Nuke allow remote attackers to inject arbitrary web script or HTML via javascript in the SRC attribute of an IMG tag.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0125" source="VUPEN">ADV-2006-0125</ref>
      <ref url="http://www.securityfocus.com/bid/16192" source="BID">16192</ref>
      <ref url="http://www.securityfocus.com/archive/1/421322" source="BUGTRAQ">20060107 Php-Nuke Pool and News Module IMG Tag Cross Site</ref>
      <ref url="http://secunia.com/advisories/18374" source="SECUNIA" adv="1">18374</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php-nuke" name="news_module">
        <vers num=""/>
      </prod>
      <prod vendor="php-nuke" name="pool_module">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2006-0186" reject="1" published="2006-01-12" name="CVE-2006-0186" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-4500.  Reason: This candidate is a duplicate of CVE-2005-4500.  Notes: All CVE users should reference CVE-2005-4500 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <vuln_types>
      <input/>
    </vuln_types>
    <refs/>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0187" published="2006-01-12" name="CVE-2006-0187" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">By design, Microsoft Visual Studio 2005 automatically executes code in the Load event of a user-defined control (UserControl1_Load function), which allows user-assisted attackers to execute arbitrary code by tricking the user into opening a malicious Visual Studio project file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0151" source="VUPEN">ADV-2006-0151</ref>
      <ref url="http://www.securityfocus.com/bid/16225" source="BID">16225</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421943/100/0/threaded" source="BUGTRAQ">20060113 Visual Studio Remote Code Execution</ref>
      <ref url="http://secunia.com/advisories/18409" source="SECUNIA" adv="1">18409</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24116" source="XF">visualstudio-usercontrol-code-execution(24116)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="visual_studio_.net">
        <vers num="2005"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0188" published="2006-02-23" name="CVE-2006-0188" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">webmail.php in SquirrelMail 1.4.0 to 1.4.5 allows remote attackers to inject arbitrary web pages into the right frame via a URL in the right_frame parameter.  NOTE: this has been called a cross-site scripting (XSS) issue, but it is different than what is normally identified as XSS.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24847" source="XF">squirrelmail-webmail-xss(24847)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0689" source="VUPEN">ADV-2006-0689</ref>
      <ref url="http://www.squirrelmail.org/security/issue/2006-02-01" source="CONFIRM">http://www.squirrelmail.org/security/issue/2006-02-01</ref>
      <ref url="http://www.securityfocus.com/bid/16756" source="BID">16756</ref>
      <ref url="http://securitytracker.com/id?1015662" source="SECTRACK">1015662</ref>
      <ref url="http://secunia.com/advisories/18985" source="SECUNIA" adv="1">18985</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10419" source="OVAL">oval:org.mitre.oval:def:10419</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0283.html" source="REDHAT">RHSA-2006:0283</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-March/msg00004.html" source="FEDORA">FEDORA-2006-133</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_05_sr.html" source="SUSE">SUSE-SR:2006:005</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:049" source="MANDRIVA">MDKSA-2006:049</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200603-09.xml" source="GENTOO">GLSA-200603-09</ref>
      <ref url="http://www.debian.org/security/2006/dsa-988" source="DEBIAN">DSA-988</ref>
      <ref url="http://secunia.com/advisories/20210" source="SECUNIA">20210</ref>
      <ref url="http://secunia.com/advisories/19960" source="SECUNIA">19960</ref>
      <ref url="http://secunia.com/advisories/19205" source="SECUNIA">19205</ref>
      <ref url="http://secunia.com/advisories/19176" source="SECUNIA">19176</ref>
      <ref url="http://secunia.com/advisories/19131" source="SECUNIA">19131</ref>
      <ref url="http://secunia.com/advisories/19130" source="SECUNIA">19130</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc" source="SGI">20060501-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squirrelmail" name="squirrelmail">
        <vers num="1.4"/>
        <vers num="1.4.1"/>
        <vers num="1.4.2"/>
        <vers num="1.4.3"/>
        <vers num="1.4.3_r3"/>
        <vers num="1.4.3_rc1"/>
        <vers num="1.4.3a"/>
        <vers num="1.4.4"/>
        <vers num="1.4.4_rc1"/>
        <vers num="1.4.5"/>
        <vers num="1.4.6_rc1"/>
        <vers num="1.4_rc1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0189" published="2006-01-13" name="CVE-2006-0189" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in eStara Softphone 3.0.1.14 through 3.0.1.46 allows remote attackers to execute arbitrary code via a long attribute (aka "a") field in the SDP data of a SIP packet on UDP port 5060.</descript>
    </desc>
    <sols>
      <sol source="nvd">This is the vendor provided solution:

"eStara has released Softphone version 3.0.1.47 to resolve the buffer overflow demonstrated in parsing SDP with long "a=" lines.  Licensed customers can download a new version via the email sent to them with purchase, customers testing may go back to http://www.estara.com/softphone/ to obtain a new free trial.   Version information can be gathered by going to Help->About.  eStara highly recommends all customers upgrade to avoid this issue.  If there's further questions please email us: softphone@estara.com.
 
eStara would like to thank ZwelL for bringing the issue to our attention."</sol>
    </sols>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24090" source="XF">estara-sip-sdp-bo(24090)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0167" source="VUPEN">ADV-2006-0167</ref>
      <ref url="http://www.securityfocus.com/bid/16213" source="BID">16213</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421596/100/0/threaded" source="BUGTRAQ" adv="1">20060111 eStara Softphone SIP stack Buffer Overflow Vulnerability</ref>
      <ref url="http://securitytracker.com/id?1015481" source="SECTRACK">1015481</ref>
      <ref url="http://secunia.com/advisories/18410" source="SECUNIA">18410</ref>
      <ref url="http://www.osvdb.org/22348" source="OSVDB">22348</ref>
    </refs>
    <vuln_soft>
      <prod vendor="estara" name="softphone">
        <vers num="3.0.1.14"/>
        <vers num="3.0.1.46"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0190" published="2006-01-13" name="CVE-2006-0190" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unspecified vulnerability in Sun Solaris 9 and 10 for the x86 platform allows local users to gain privileges or cause a denial of service (panic) via unspecified vectors, possibly involving functions from the mm driver.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/searchproxy/document.do?assetkey=1-26-102066-1" source="SUNALERT" patch="1" adv="1">102066</ref>
      <ref url="http://secunia.com/advisories/18421" source="SECUNIA" patch="1" adv="1">18421</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0165" source="VUPEN">ADV-2006-0165</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24084" source="XF">solaris-unspecified-root-access(24084)</ref>
      <ref url="http://www.securityfocus.com/bid/16224" source="BID">16224</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-056.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-056.htm</ref>
      <ref url="http://securitytracker.com/id?1015478" source="SECTRACK">1015478</ref>
      <ref url="http://secunia.com/advisories/19087" source="SECUNIA">19087</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:702" source="OVAL" sig="1">oval:org.mitre.oval:def:702</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="10.0" edition=""/>
        <vers num="10.0" edition=":sparc"/>
        <vers num="9.0" edition=""/>
        <vers num="9.0" edition=":sparc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0191" published="2006-01-13" name="CVE-2006-0191" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">Unspecified vulnerability in Sun Solaris 10 allows local users to cause a denial of service (null dereference) via unspecified vectors involving the use of the find command on the "/proc" filesystem. NOTE: due to the vagueness of the vendor advisory, it is not clear whether this is related to CVE-2005-3250.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/searchproxy/document.do?assetkey=1-26-102108-1" source="SUNALERT" patch="1" adv="1">102108</ref>
      <ref url="http://secunia.com/advisories/18420" source="SECUNIA" patch="1" adv="1">18420</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0166" source="VUPEN">ADV-2006-0166</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24085" source="XF">solaris-find-proc-dos(24085)</ref>
      <ref url="http://www.securityfocus.com/bid/16222" source="BID">16222</ref>
      <ref url="http://www.osvdb.org/22347" source="OSVDB">22347</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-056.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-056.htm</ref>
      <ref url="http://securitytracker.com/id?1015479" source="SECTRACK">1015479</ref>
      <ref url="http://secunia.com/advisories/19087" source="SECUNIA">19087</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1608" source="OVAL" sig="1">oval:org.mitre.oval:def:1608</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="10.0" edition=""/>
        <vers num="10.0" edition=":sparc"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0192" published="2006-01-13" name="CVE-2006-0192" modified="2011-08-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in Login_Validate.asp in ASPSurvey 1.10 allows remote attackers to execute arbitrary SQL commands via the Password parameter to login.asp.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24087" source="XF">aspsurvey-loginvalidate-sql-injection(24087)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0164" source="VUPEN" adv="1">ADV-2006-0164</ref>
      <ref url="http://www.securityfocus.com/bid/16496" source="BID">16496</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423949/100/0/threaded" source="BUGTRAQ">20060204 sql injection in ASP Survey</ref>
      <ref url="http://www.osvdb.org/22342" source="OSVDB">22342</ref>
      <ref url="http://securityreason.com/securityalert/414" source="SREASON">414</ref>
      <ref url="http://secunia.com/advisories/18422" source="SECUNIA" adv="1">18422</ref>
    </refs>
    <vuln_soft>
      <prod vendor="philip_loftin" name="aspsurvey">
        <vers num="1.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0193" published="2006-01-13" name="CVE-2006-0193" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Hosting Control Panel (psoft.hsphere.CP) in Positive Software H-Sphere 2.4.3 Patch 8 and earlier allows remote attackers to inject arbitrary web script or HTML via the login parameter in a login action.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421704/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20060112 H-Sphere Security Vulnerability</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0172" source="VUPEN">ADV-2006-0172</ref>
      <ref url="http://www.psoft.net/HSdocumentation/versions/?v=all&amp;p=r" source="CONFIRM">http://www.psoft.net/HSdocumentation/versions/?v=all&amp;p=r</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24096" source="XF">hsphere-login-xss(24096)</ref>
      <ref url="http://www.psoft.net/HSdocumentation/versions/index.php?v=243p9&amp;p=r" source="CONFIRM">http://www.psoft.net/HSdocumentation/versions/index.php?v=243p9&amp;p=r</ref>
      <ref url="http://www.osvdb.org/22372" source="OSVDB">22372</ref>
      <ref url="http://secunia.com/advisories/18447" source="SECUNIA">18447</ref>
    </refs>
    <vuln_soft>
      <prod vendor="positive_software" name="h-sphere">
        <vers num="2.4.1"/>
        <vers num="2.4.1_patch_1"/>
        <vers num="2.4.1_patch_2"/>
        <vers num="2.4.1_patch_3"/>
        <vers num="2.4.1_patch_4"/>
        <vers num="2.4.1_patch_5"/>
        <vers num="2.4.1_patch_6"/>
        <vers num="2.4.1_patch_7"/>
        <vers num="2.4.2"/>
        <vers num="2.4.2_beta_1"/>
        <vers num="2.4.2_beta_2"/>
        <vers num="2.4.2_beta_3"/>
        <vers num="2.4.2_patch_1"/>
        <vers num="2.4.2_patch_2"/>
        <vers num="2.4.2_patch_3"/>
        <vers num="2.4.2_patch_4"/>
        <vers num="2.4.2_patch_5"/>
        <vers num="2.4.2_rc1"/>
        <vers num="2.4.2_rc2"/>
        <vers num="2.4.3"/>
        <vers num="2.4.3_beta_1"/>
        <vers num="2.4.3_beta_2"/>
        <vers num="2.4.3_patch_1"/>
        <vers num="2.4.3_patch_2"/>
        <vers num="2.4.3_patch_3"/>
        <vers num="2.4.3_patch_4"/>
        <vers num="2.4.3_patch_5"/>
        <vers num="2.4.3_patch_6"/>
        <vers num="2.4.3_patch_7"/>
        <vers num="2.4.3_patch_8"/>
        <vers num="2.4.3_rc1"/>
        <vers num="2.4.3_rc2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0194" published="2006-01-13" name="CVE-2006-0194" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in default.asp in FogBugz 4.029, and other versions before 4.0.33, allows remote attackers to inject arbitrary web script or HTML via the dest parameter in the pgLogon page.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16216" source="BID" patch="1">16216</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0174" source="VUPEN">ADV-2006-0174</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421729/100/0/threaded" source="BUGTRAQ" adv="1">20060112 FogBugz Cross Site Scripting Vulnerability</ref>
      <ref url="http://www.fogcreek.com/FogBugz/KB/releaseNotes/WhatsNewInFogBugz4.0.33.html" source="CONFIRM">http://www.fogcreek.com/FogBugz/KB/releaseNotes/WhatsNewInFogBugz4.0.33.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24103" source="XF">fogbugz-login-xss(24103)</ref>
      <ref url="http://www.osvdb.org/22370" source="OSVDB">22370</ref>
      <ref url="http://secunia.com/advisories/18443" source="SECUNIA">18443</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fog_creek_software" name="fogbugz">
        <vers prev="1" num="4.029"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0195" published="2006-02-23" name="CVE-2006-0195" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Interpretation conflict in the MagicHTML filter in SquirrelMail 1.4.0 to 1.4.5 allows remote attackers to conduct cross-site scripting (XSS) attacks via style sheet specifiers with invalid (1) "/*" and "*/" comments, or (2) a newline in a "url" specifier, which is processed by certain web browsers including Internet Explorer.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24848" source="XF">squirrelmail-magichtml-xss(24848)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0689" source="VUPEN">ADV-2006-0689</ref>
      <ref url="http://www.squirrelmail.org/security/issue/2006-02-10" source="CONFIRM">http://www.squirrelmail.org/security/issue/2006-02-10</ref>
      <ref url="http://www.securityfocus.com/bid/16756" source="BID">16756</ref>
      <ref url="http://securitytracker.com/id?1015662" source="SECTRACK">1015662</ref>
      <ref url="http://secunia.com/advisories/18985" source="SECUNIA" adv="1">18985</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9548" source="OVAL">oval:org.mitre.oval:def:9548</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0283.html" source="REDHAT">RHSA-2006:0283</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-March/msg00004.html" source="FEDORA">FEDORA-2006-133</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_05_sr.html" source="SUSE">SUSE-SR:2006:005</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:049" source="MANDRIVA">MDKSA-2006:049</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200603-09.xml" source="GENTOO">GLSA-200603-09</ref>
      <ref url="http://www.debian.org/security/2006/dsa-988" source="DEBIAN">DSA-988</ref>
      <ref url="http://secunia.com/advisories/20210" source="SECUNIA">20210</ref>
      <ref url="http://secunia.com/advisories/19960" source="SECUNIA">19960</ref>
      <ref url="http://secunia.com/advisories/19205" source="SECUNIA">19205</ref>
      <ref url="http://secunia.com/advisories/19176" source="SECUNIA">19176</ref>
      <ref url="http://secunia.com/advisories/19131" source="SECUNIA">19131</ref>
      <ref url="http://secunia.com/advisories/19130" source="SECUNIA">19130</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc" source="SGI">20060501-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squirrelmail" name="squirrelmail">
        <vers num="1.4"/>
        <vers num="1.4.1"/>
        <vers num="1.4.2"/>
        <vers num="1.4.3"/>
        <vers num="1.4.3_r3"/>
        <vers num="1.4.3_rc1"/>
        <vers num="1.4.3a"/>
        <vers num="1.4.4"/>
        <vers num="1.4.4_rc1"/>
        <vers num="1.4.5"/>
        <vers num="1.4.6_rc1"/>
        <vers num="1.4_rc1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0196" published="2006-01-13" name="CVE-2006-0196" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Unspecified vulnerability in Serial line sniffer (aka slsnif) 0.4.4 allows local users to gain privileges via a long value of the HOME environment variable, possibly because of a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24082" source="XF">slsnif-home-bo(24082)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0212" source="VUPEN">ADV-2006-0212</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421583/100/0/threaded" source="BUGTRAQ">20060111 Serial Line Sniffer 0.4.4 Buffer Overflow</ref>
      <ref url="http://shellcoders.com/sintigan/slsnif-ploit.pl" source="MISC">http://shellcoders.com/sintigan/slsnif-ploit.pl</ref>
      <ref url="http://secunia.com/advisories/18497" source="SECUNIA">18497</ref>
    </refs>
    <vuln_soft>
      <prod vendor="serial_line_sniffer" name="serial_line_sniffer">
        <vers num="0.4.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0197" published="2006-01-13" name="CVE-2006-0197" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The XClientMessageEvent struct used in certain components of X.Org 6.8.2 and earlier, possibly including (1) the X server and (2) Xlib, uses a "long" specifier for elements of the l array, which results in inconsistent sizes in the struct on 32-bit versus 64-bit platforms, and might allow attackers to cause a denial of service (application crash) and possibly conduct other attacks.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421256/100/0/threaded" source="BUGTRAQ" adv="1">20060108 xorg server 6.8.2 and below on 64bit arch</ref>
    </refs>
    <vuln_soft>
      <prod vendor="x.org" name="x.org">
        <vers prev="1" num="6.8.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0198" published="2006-01-13" name="CVE-2006-0198" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in a certain module, possibly poll or Pool, for XOOPS allows remote attackers to inject arbitrary web script or HTML via JavaScript in the SRC attribute of an IMG element in a comment.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.xoops.org/modules/newbb/viewtopic.php?topic_id=45637&amp;forum=2&amp;post_id=200481" source="MISC" adv="1">http://www.xoops.org/modules/newbb/viewtopic.php?topic_id=45637&amp;forum=2&amp;post_id=200481</ref>
      <ref url="http://www.securityfocus.com/bid/16189" source="BID">16189</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421325/100/0/threaded" source="BUGTRAQ">20060107 Xoops Pool Module IMG Tag Cross Site Scripting</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24091" source="XF">xoops-pool-imagetag-xss(24091)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xoops" name="xoops_pool_module">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0199" published="2006-01-13" name="CVE-2006-0199" modified="2011-08-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in news.asp in Mini-Nuke CMS System 1.8.2 and earlier allows remote attackers to execute arbitrary SQL commands via the hid parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24098" source="XF">mininuke-news-sql-injection(24098)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0173" source="VUPEN" adv="1">ADV-2006-0173</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421727/100/0/threaded" source="BUGTRAQ" adv="1">20060113 Advisory: MiniNuke CMS System &lt;= 1.8.2 (news.asp) SQL Injectionvulnerability</ref>
      <ref url="http://www.osvdb.org/22384" source="OSVDB">22384</ref>
      <ref url="http://www.nukedx.com/?viewdoc=7" source="MISC">http://www.nukedx.com/?viewdoc=7</ref>
      <ref url="http://securityreason.com/securityalert/340" source="SREASON">340</ref>
      <ref url="http://secunia.com/advisories/18439" source="SECUNIA" adv="1">18439</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0439.html" source="FULLDISC" adv="1">20060112 Advisory: MiniNuke CMS System &lt;= 1.8.2 (news.asp) SQL Injection vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mini-nuke" name="cms_system">
        <vers prev="1" num="1.8.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0200" published="2006-01-13" name="CVE-2006-0200" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Format string vulnerability in the error-reporting feature in the mysqli extension in PHP 5.1.0 and 5.1.1 might allow remote attackers to execute arbitrary code via format string specifiers in MySQL error messages.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24095" source="XF" patch="1">php-extmysqli-format-string(24095)</ref>
      <ref url="http://www.securityfocus.com/bid/16219" source="BID" patch="1">16219</ref>
      <ref url="http://www.php.net/release_5_1_2.php" source="CONFIRM" patch="1">http://www.php.net/release_5_1_2.php</ref>
      <ref url="http://secunia.com/advisories/18431" source="SECUNIA" patch="1" adv="1">18431</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0369" source="VUPEN">ADV-2006-0369</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0177" source="VUPEN">ADV-2006-0177</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421705/100/0/threaded" source="BUGTRAQ" adv="1">20060112 Advisory 02/2006: PHP ext/mysqli Format String Vulnerability</ref>
      <ref url="http://www.hardened-php.net/advisory_022006.113.html" source="MISC" adv="1">http://www.hardened-php.net/advisory_022006.113.html</ref>
      <ref url="http://securitytracker.com/id?1015485" source="SECTRACK">1015485</ref>
      <ref url="http://securityreason.com/securityalert/337" source="SREASON">337</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="5.1"/>
        <vers num="5.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0201" published="2006-01-13" name="CVE-2006-0201" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Dave Nielsen and Patrick Breitenbach PayPal Web Services (aka PHP Toolkit) 0.50, and possibly earlier versions, allows remote attackers to enter false payment entries into the log file via HTTP POST requests to ipn_success.php.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0183" source="VUPEN">ADV-2006-0183</ref>
      <ref url="http://www.uinc.ru/articles/vuln/ptpaypal050.shtml" source="MISC" adv="1">http://www.uinc.ru/articles/vuln/ptpaypal050.shtml</ref>
      <ref url="http://www.securityfocus.com/bid/16218" source="BID">16218</ref>
      <ref url="http://www.securityfocus.com/archive/1/421739" source="BUGTRAQ" adv="1">20060112 Multiple PHP Toolkit for PayPal Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/18444" source="SECUNIA" adv="1">18444</ref>
      <ref url="http://www.osvdb.org/22378" source="OSVDB">22378</ref>
    </refs>
    <vuln_soft>
      <prod vendor="paypal" name="php_toolkit">
        <vers prev="1" num="0.50"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0202" published="2006-01-13" name="CVE-2006-0202" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">Dave Nielsen and Patrick Breitenbach PayPal Web Services (aka PHP Toolkit) 0.50 and possibly earlier has (1) world-readable permissions for ipn/logs/ipn_success.txt, which allows local users to view sensitive information (payment data), and (2) world-writable permissions for ipn/logs, which allows local users to delete or replace payment data.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0183" source="VUPEN">ADV-2006-0183</ref>
      <ref url="http://www.uinc.ru/articles/vuln/ptpaypal050.shtml" source="MISC" adv="1">http://www.uinc.ru/articles/vuln/ptpaypal050.shtml</ref>
      <ref url="http://www.securityfocus.com/bid/16218" source="BID">16218</ref>
      <ref url="http://www.securityfocus.com/archive/1/421739" source="BUGTRAQ" adv="1">20060112 Multiple PHP Toolkit for PayPal Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/18444" source="SECUNIA" adv="1">18444</ref>
      <ref url="http://www.osvdb.org/22379" source="OSVDB">22379</ref>
    </refs>
    <vuln_soft>
      <prod vendor="paypal" name="php_toolkit">
        <vers prev="1" num="0.50"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0203" published="2006-01-13" name="CVE-2006-0203" modified="2011-10-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">membership.asp in Mini-Nuke CMS System 1.8.2 and earlier does not verify the old password when changing a password, which allows remote attackers to change the passwords of other members via a lostpassnew action with a modified x parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24101" source="XF">mininuke-membership-change-password(24101)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0173" source="VUPEN" adv="1">ADV-2006-0173</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421748/100/0/threaded" source="BUGTRAQ" adv="1">20060113 Advisory: MiniNuke CMS System &lt;= 1.8.2 (membership.asp) remoteuser password change exploit</ref>
      <ref url="http://www.osvdb.org/22385" source="OSVDB">22385</ref>
      <ref url="http://securityreason.com/securityalert/344" source="SREASON">344</ref>
      <ref url="http://secunia.com/advisories/18439" source="SECUNIA" adv="1">18439</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0439.html" source="FULLDISC" adv="1">20060112 Advisory: MiniNuke CMS System &lt;= 1.8.2 (news.asp) SQL Injection vulnerability</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0437.html" source="FULLDISC" adv="1">20060112 Advisory: MiniNuke CMS System &lt;= 1.8.2 (membership.asp) remote user password change exploit</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2006-01/0483.html" source="BUGTRAQ" adv="1">20060129 [xpl#2] MiniNuke 1.8.2 - change member's passwrod &lt; Perl ></ref>
    </refs>
    <vuln_soft>
      <prod vendor="mini-nuke" name="cms_system">
        <vers prev="1" num="1.8.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0204" published="2006-01-13" name="CVE-2006-0204" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Wordcircle 2.17 allow remote attackers to inject arbitrary web script or HTML via (1) the "Course name" field in index.php when the frm parameter has the value "mine" and (2) possibly certain other fields in unspecified scripts.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24106" source="XF">wordcircle-index-xss(24106)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0185" source="VUPEN">ADV-2006-0185</ref>
      <ref url="http://www.securityfocus.com/bid/16227" source="BID">16227</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421746/100/0/threaded" source="BUGTRAQ" adv="1">20060112 [eVuln] Wordcircle Multiple SQL Injection &amp; XSS Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/22359" source="OSVDB">22359</ref>
      <ref url="http://secunia.com/advisories/18440" source="SECUNIA" adv="1">18440</ref>
      <ref url="http://evuln.com/vulns/28/summary.html" source="MISC" adv="1">http://evuln.com/vulns/28/summary.html</ref>
      <ref url="http://securityreason.com/securityalert/345" source="SREASON">345</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordcircle" name="wordcircle">
        <vers num="2.17"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0205" published="2006-01-13" name="CVE-2006-0205" modified="2011-09-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Wordcircle 2.17 allow remote attackers to (1) execute arbitrary SQL commands and bypass authentication via the password field in the login action to index.php (involving v_login.php and s_user.php) and (2) have other unknown impact via certain other fields in unspecified scripts.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24108" source="XF">wordcircle-login-security-bypass(24108)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24105" source="XF">wordcircle-sql-injection(24105)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0185" source="VUPEN" adv="1">ADV-2006-0185</ref>
      <ref url="http://www.securityfocus.com/bid/16227" source="BID">16227</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421746/100/0/threaded" source="BUGTRAQ">20060112 [eVuln] Wordcircle Multiple SQL Injection &amp; XSS Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421745/100/0/threaded" source="BUGTRAQ" adv="1">20060112 [eVuln] Wordcircle Authentication Bypass</ref>
      <ref url="http://www.osvdb.org/22358" source="OSVDB">22358</ref>
      <ref url="http://securityreason.com/securityalert/346" source="SREASON">346</ref>
      <ref url="http://securityreason.com/securityalert/345" source="SREASON">345</ref>
      <ref url="http://secunia.com/advisories/18440" source="SECUNIA" adv="1">18440</ref>
      <ref url="http://evuln.com/vulns/28/summary.html" source="MISC">http://evuln.com/vulns/28/summary.html</ref>
      <ref url="http://evuln.com/vulns/27/summary.html" source="MISC">http://evuln.com/vulns/27/summary.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordcircle" name="wordcircle">
        <vers num="2.17"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0206" published="2006-01-13" name="CVE-2006-0206" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Eval injection vulnerability in Light Weight Calendar (LWC) 1.0 (20040909) and earlier allows remote attackers to execute arbitrary PHP code via the date parameter in cal.php, which is included by index.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16229" source="BID">16229</ref>
      <ref url="http://secunia.com/advisories/18450" source="SECUNIA" adv="1">18450</ref>
      <ref url="http://evuln.com/vulns/29/summary.html" source="MISC" adv="1">http://evuln.com/vulns/29/summary.html</ref>
      <ref url="http://evuln.com/vulns/29/exploit.html" source="MISC">http://evuln.com/vulns/29/exploit.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24110" source="XF">lwc-cal-execute-code(24110)</ref>
      <ref url="http://www.osvdb.org/22376" source="OSVDB">22376</ref>
      <ref url="http://attrition.org/pipermail/vim/2006-March/000612.html" source="VIM">20060318 Source VERIFY - Light Weight Calendar issue is eval injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="light_weight_calendar" name="light_weight_calendar">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0207" published="2006-01-13" name="CVE-2006-0207" modified="2011-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple HTTP response splitting vulnerabilities in PHP 5.1.1 allow remote attackers to inject arbitrary HTTP headers via a crafted Set-Cookie header, related to the (1) session extension (aka ext/session) and the (2) header function.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24094" source="XF" patch="1">php-session-response-splitting(24094)</ref>
      <ref url="http://www.securityfocus.com/bid/16220" source="BID" patch="1">16220</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200603-22.xml" source="GENTOO" patch="1" adv="1">GLSA-200603-22</ref>
      <ref url="http://securitytracker.com/id?1015484" source="SECTRACK" patch="1" adv="1">1015484</ref>
      <ref url="http://secunia.com/advisories/19355" source="SECUNIA" patch="1" adv="1">19355</ref>
      <ref url="http://secunia.com/advisories/19179" source="SECUNIA" patch="1" adv="1">19179</ref>
      <ref url="http://secunia.com/advisories/18697" source="SECUNIA" patch="1" adv="1">18697</ref>
      <ref url="http://secunia.com/advisories/18431" source="SECUNIA" patch="1" adv="1">18431</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0369" source="VUPEN" adv="1">ADV-2006-0369</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0177" source="VUPEN" adv="1">ADV-2006-0177</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-261-1" source="UBUNTU">USN-261-1</ref>
      <ref url="http://www.php.net/release_5_1_2.php" source="CONFIRM">http://www.php.net/release_5_1_2.php</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:028" source="MANDRIVA">MDKSA-2006:028</ref>
      <ref url="http://www.hardened-php.net/advisory_012006.112.html" source="MISC" adv="1">http://www.hardened-php.net/advisory_012006.112.html</ref>
      <ref url="http://www.debian.org/security/2007/dsa-1331" source="DEBIAN">DSA-1331</ref>
      <ref url="http://secunia.com/advisories/25945" source="SECUNIA">25945</ref>
      <ref url="http://secunia.com/advisories/19012" source="SECUNIA" adv="1">19012</ref>
      <ref url="http://lists.suse.de/archive/suse-security-announce/2006-Feb/0008.html" source="SUSE">SUSE-SR:2006:004</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="5.0" edition="rc1"/>
        <vers num="5.0" edition="rc2"/>
        <vers num="5.0" edition="rc3"/>
        <vers num="5.0.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4"/>
        <vers num="5.0.5"/>
        <vers num="5.1"/>
        <vers num="5.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0208" published="2006-01-13" name="CVE-2006-0208" modified="2011-09-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in PHP 4.4.1 and 5.1.1, when display_errors and html_errors are on, allow remote attackers to inject arbitrary web script or HTML via inputs to PHP applications that are not filtered when they are included in the resulting error message.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16803" source="BID" patch="1">16803</ref>
      <ref url="http://www.php.net/release_5_1_2.php" source="CONFIRM" patch="1">http://www.php.net/release_5_1_2.php</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200603-22.xml" source="GENTOO" patch="1" adv="1">GLSA-200603-22</ref>
      <ref url="http://secunia.com/advisories/19355" source="SECUNIA" patch="1" adv="1">19355</ref>
      <ref url="http://secunia.com/advisories/19179" source="SECUNIA" patch="1" adv="1">19179</ref>
      <ref url="http://secunia.com/advisories/18697" source="SECUNIA" patch="1" adv="1">18697</ref>
      <ref url="http://secunia.com/advisories/18431" source="SECUNIA" patch="1" adv="1">18431</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=178028" source="MISC">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=178028</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2685" source="VUPEN" adv="1">ADV-2006-2685</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0369" source="VUPEN" adv="1">ADV-2006-0369</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0177" source="VUPEN" adv="1">ADV-2006-0177</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-261-1" source="UBUNTU">USN-261-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0501.html" source="REDHAT" adv="1">RHSA-2006:0501</ref>
      <ref url="http://www.php.net/ChangeLog-4.php#4.4.2" source="CONFIRM">http://www.php.net/ChangeLog-4.php#4.4.2</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:028" source="MANDRIVA">MDKSA-2006:028</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-160.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-160.htm</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-129.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-129.htm</ref>
      <ref url="http://secunia.com/advisories/21564" source="SECUNIA" adv="1">21564</ref>
      <ref url="http://secunia.com/advisories/21252" source="SECUNIA" adv="1">21252</ref>
      <ref url="http://secunia.com/advisories/20951" source="SECUNIA" adv="1">20951</ref>
      <ref url="http://secunia.com/advisories/20222" source="SECUNIA" adv="1">20222</ref>
      <ref url="http://secunia.com/advisories/20210" source="SECUNIA" adv="1">20210</ref>
      <ref url="http://secunia.com/advisories/19832" source="SECUNIA" adv="1">19832</ref>
      <ref url="http://secunia.com/advisories/19012" source="SECUNIA" adv="1">19012</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2006-0549.html" source="REDHAT" adv="1">RHSA-2006:0549</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2006-0276.html" source="REDHAT">RHSA-2006:0276</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10064" source="OVAL">oval:org.mitre.oval:def:10064</ref>
      <ref url="http://lists.suse.de/archive/suse-security-announce/2006-Feb/0008.html" source="SUSE">SUSE-SR:2006:004</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc" source="SGI">20060501-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="4.0" edition="beta1"/>
        <vers num="4.0" edition="beta2"/>
        <vers num="4.0" edition="beta3"/>
        <vers num="4.0" edition="beta4"/>
        <vers num="4.0" edition="beta_4_patch1"/>
        <vers num="4.0" edition="rc1"/>
        <vers num="4.0" edition="rc2"/>
        <vers num="4.0.0"/>
        <vers num="4.0.1"/>
        <vers num="4.0.2"/>
        <vers num="4.0.3"/>
        <vers num="4.0.4"/>
        <vers num="4.0.5"/>
        <vers num="4.0.6"/>
        <vers num="4.1.0"/>
        <vers num="4.1.1"/>
        <vers num="4.1.2"/>
        <vers num="4.2.0"/>
        <vers num="4.2.1"/>
        <vers num="4.2.2"/>
        <vers num="4.2.3"/>
        <vers num="4.3"/>
        <vers num="4.3.1"/>
        <vers num="4.3.10"/>
        <vers num="4.3.11"/>
        <vers num="4.3.2"/>
        <vers num="4.3.3"/>
        <vers num="4.3.4"/>
        <vers num="4.3.5"/>
        <vers num="4.3.6"/>
        <vers num="4.3.7"/>
        <vers num="4.3.8"/>
        <vers num="4.3.9"/>
        <vers num="4.4.1"/>
        <vers num="4.4.2"/>
        <vers num="5.0.0" edition="beta1"/>
        <vers num="5.0.0" edition="beta2"/>
        <vers num="5.0.0" edition="beta3"/>
        <vers num="5.0.0" edition="rc1"/>
        <vers num="5.0.0" edition="rc2"/>
        <vers num="5.0.0" edition="rc3"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4"/>
        <vers num="5.0.5"/>
        <vers num="5.1.0"/>
        <vers num="5.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0209" published="2006-01-13" name="CVE-2006-0209" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in general_functions.php in TankLogger 2.4 allows remote attackers to execute arbitrary SQL commands via the (1) livestock_id parameter to showInfo.php and (2) tank_id parameter, possibly to livestock.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0153" source="VUPEN">ADV-2006-0153</ref>
      <ref url="http://evuln.com/vulns/26/summary.html" source="MISC">http://evuln.com/vulns/26/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24080" source="XF">tanklogger-generalfunctions-sql-injection(24080)</ref>
      <ref url="http://www.securityfocus.com/bid/16228" source="BID">16228</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421743/100/0/threaded" source="BUGTRAQ">20060112 [eVuln] TankLogger SQL Injection Vulnerability</ref>
      <ref url="http://www.osvdb.org/22369" source="OSVDB">22369</ref>
      <ref url="http://www.osvdb.org/22368" source="OSVDB">22368</ref>
      <ref url="http://securityreason.com/securityalert/341" source="SREASON">341</ref>
      <ref url="http://secunia.com/advisories/18441" source="SECUNIA">18441</ref>
      <ref url="http://attrition.org/pipermail/vim/2006-January/000480.html" source="VIM">20060113 Verified TankLogger SQl inject by source inspection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tanklogger" name="tanklogger">
        <vers num="2.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0210" published="2006-01-13" name="CVE-2006-0210" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Interspire TrackPoint NX before 0.1 allows remote attackers to inject arbitrary web script or HTML via the username parameter when using the Login page.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0175" source="VUPEN">ADV-2006-0175</ref>
      <ref url="http://www.securityfocus.com/bid/16214" source="BID">16214</ref>
      <ref url="http://www.interspire.com/forum/showthread.php?p=29606" source="CONFIRM">http://www.interspire.com/forum/showthread.php?p=29606</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24112" source="XF">trackpointnx-login-xss(24112)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421740/100/0/threaded" source="BUGTRAQ">20060112 Interspire TrackPoint NX XSS Vulnerability</ref>
      <ref url="http://www.osvdb.org/22377" source="OSVDB">22377</ref>
      <ref url="http://secunia.com/advisories/18445" source="SECUNIA">18445</ref>
    </refs>
    <vuln_soft>
      <prod vendor="interspire" name="trackpoint_nx">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0211" published="2006-01-13" name="CVE-2006-0211" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in forgotPassword.asp in Helm Hosting Control Panel 3.2.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the txtEmailAddress parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0203" source="VUPEN">ADV-2006-0203</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421791/100/0/threaded" source="BUGTRAQ">20060112 Helm XSS Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24139" source="XF">helm-forgotpassword-xss(24139)</ref>
      <ref url="http://www.webhostautomation.com/webhost-301" source="CONFIRM">http://www.webhostautomation.com/webhost-301</ref>
      <ref url="http://www.securityfocus.com/bid/16234" source="BID">16234</ref>
      <ref url="http://www.osvdb.org/22454" source="OSVDB">22454</ref>
      <ref url="http://secunia.com/advisories/18492" source="SECUNIA">18492</ref>
    </refs>
    <vuln_soft>
      <prod vendor="helm_hosting" name="helm_hosting_control_panel">
        <vers num="3.2.8"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0212" published="2006-01-13" name="CVE-2006-0212" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in OBEX Push services in Toshiba Bluetooth Stack 4.00.23(T) and earlier allows remote attackers to upload arbitrary files to arbitrary remote locations specified by .. (dot dot) sequences, as demonstrated by ..\\ sequences in the RFILE argument of ussp-push.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0184" source="VUPEN">ADV-2006-0184</ref>
      <ref url="http://www.securityfocus.com/bid/16236" source="BID">16236</ref>
      <ref url="http://www.digitalmunition.com/DMA%5B2006-0112a%5D.txt" source="MISC" adv="1">http://www.digitalmunition.com/DMA%5B2006-0112a%5D.txt</ref>
      <ref url="http://secunia.com/advisories/18437" source="SECUNIA" adv="1">18437</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=113712413907526&amp;w=2" source="FULLDISC" adv="1">20060113 DMA[2006-0112a] - 'Toshiba Bluetooth Stack Directory Transversal'</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421993/100/0/threaded" source="BUGTRAQ">20060113 DMA[2006-0112a] - 'Toshiba Bluetooth Stack Directory Transversal'</ref>
      <ref url="http://www.osvdb.org/22380" source="OSVDB">22380</ref>
      <ref url="http://securitytracker.com/id?1015486" source="SECTRACK">1015486</ref>
      <ref url="http://aps.toshiba-tro.de/bluetooth/pages/driverinfo.php?txt=sp2" source="MISC">http://aps.toshiba-tro.de/bluetooth/pages/driverinfo.php?txt=sp2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="toshiba" name="bluetooth_stack">
        <vers num="3.00.11"/>
        <vers num="3.00.12"/>
        <vers num="3.00.31a"/>
        <vers num="3.00.32"/>
        <vers num="3.01.03"/>
        <vers num="3.10.00"/>
        <vers num="3.20.00"/>
        <vers num="3.20.01"/>
        <vers num="3.20.02"/>
        <vers num="3.20.04"/>
        <vers num="4.00.01t"/>
        <vers num="4.00.11"/>
        <vers prev="1" num="4.00.23t"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0213" published="2006-01-13" name="CVE-2006-0213" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Kolab Server 2.0.1, 2.0.2 and development versions pre-2.1-20051215 and earlier, when authenticating users via secure SMTP, stores authentication credentials in plaintext in the postfix.log file, which allows local users to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18438" source="SECUNIA" patch="1" adv="1">18438</ref>
      <ref url="http://kolab.org/security/kolab-vendor-notice-08.txt" source="CONFIRM" patch="1" adv="1">http://kolab.org/security/kolab-vendor-notice-08.txt</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0186" source="VUPEN">ADV-2006-0186</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24123" source="XF">kolab-smtp-logging(24123)</ref>
      <ref url="http://www.osvdb.org/22381" source="OSVDB">22381</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kolab" name="kolab_groupware_server">
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers prev="1" num="2005-12-15_pre2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0214" published="2006-01-15" name="CVE-2006-0214" modified="2008-09-20" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Eval injection vulnerability in ezDatabase 2.0 and earlier allows remote attackers to execute arbitrary PHP code via the db_id parameter to visitorupload.php, as demonstrated using phpinfo and include function calls.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24136" source="XF">ezdatabase-visitorupload-file-include(24136)</ref>
      <ref url="http://www.securityfocus.com/bid/16237" source="BID">16237</ref>
      <ref url="http://securityreason.com/securityalert/351" source="SREASON">351</ref>
      <ref url="http://secunia.com/advisories/18043" source="SECUNIA">18043</ref>
      <ref url="http://pridels0.blogspot.com/2006/01/ezdatabase-20-and-below.html" source="MISC">http://pridels0.blogspot.com/2006/01/ezdatabase-20-and-below.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="indexcor" name="ezdatabase">
        <vers num="2.0"/>
        <vers num="2.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0215" published="2006-01-16" name="CVE-2006-0215" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in admin.php in QualityEBiz Quality PPC (QPPC) 1.0 build 1644 allows remote attackers to inject arbitrary web script or HTML via the cpage parameter.  NOTE: this issue might be resultant from CVE-2006-0216.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.osvdb.org/22352" source="OSVDB">22352</ref>
      <ref url="http://osvdb.org/ref/22/22352-qualityppc.txt" source="MISC" adv="1">http://osvdb.org/ref/22/22352-qualityppc.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qualityebiz" name="quality_ppc">
        <vers num="1.0_build_1644"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0216" published="2006-01-16" name="CVE-2006-0216" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">admin.php in QualityEBiz Quality PPC (QPPC) 1.0 build 1644 allows remote attackers to obtain sensitive information, possibly the installation path of the application, via unspecified "meta characters" to the cpage parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.osvdb.org/22353" source="OSVDB">22353</ref>
      <ref url="http://osvdb.org/ref/22/22353-qualityppc.txt" source="MISC">http://osvdb.org/ref/22/22353-qualityppc.txt</ref>
      <ref url="http://osvdb.org/ref/22/22352-qualityppc.txt" source="MISC">http://osvdb.org/ref/22/22352-qualityppc.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qualityebiz" name="quality_ppc">
        <vers num="1.0_build_1644"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0217" published="2006-01-16" name="CVE-2006-0217" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Ultimate Auction 3.67 allow remote attackers to inject arbitrary web script or HTML via the (1) item parameter in item.pl and (2) category parameter in itemlist.pl, which reflects the XSS in an error message. NOTE: the affected version might be wrong since the current version as of 20060116 is 3.6.1.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0187" source="VUPEN">ADV-2006-0187</ref>
      <ref url="http://www.securityfocus.com/bid/16239" source="BID">16239</ref>
      <ref url="http://www.osvdb.org/22444" source="OSVDB">22444</ref>
      <ref url="http://www.osvdb.org/22443" source="OSVDB">22443</ref>
      <ref url="http://secunia.com/advisories/18477" source="SECUNIA" adv="1">18477</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0517.html" source="FULLDISC">20060115 Ultimate Auction &lt;=3.67</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24138" source="XF">ultimate-auction-item-xss(24138)</ref>
      <ref url="http://www.securityfocus.com/bid/16254" source="BID">16254</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ultimate_auction" name="ultimate_auction">
        <vers num="3.67"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0218" published="2006-01-16" name="CVE-2006-0218" modified="2013-01-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in MyBulletinBoard (MyBB) before 1.0.2 have unspecified impact and attack vectors, related to (1) admin/moderate.php, (2) admin/themes.php, (3) inc/functions.php, (4) inc/functions_upload.php, (5) printthread.php, and (6) usercp.php, and probably related to SQL injection.  NOTE: it is likely that this issue subsumes CVE-2005-4602 and CVE-2005-4603.  However, since the vendor advisory is vague and additional files are mentioned, is is likely that this contains at least one distinct vulnerability from CVE-2005-4602 and CVE-2005-4603.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://community.mybboard.net/showthread.php?tid=5852" source="CONFIRM" patch="1" adv="1">http://community.mybboard.net/showthread.php?tid=5852</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mybb" name="mybb">
        <vers num="1.0" edition="beta4"/>
        <vers num="1.0" edition="pr1"/>
        <vers num="1.0" edition="pr2"/>
        <vers num="1.0" edition="rc1"/>
        <vers num="1.0" edition="rc2"/>
        <vers num="1.0" edition="rc3"/>
        <vers num="1.0" edition="rc4"/>
        <vers num="1.00"/>
        <vers prev="1" num="1.01"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0219" published="2006-01-16" name="CVE-2006-0219" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The original distribution of MyBulletinBoard (MyBB) to update from older versions to 1.0.2 omits or includes older versions of certain critical files, which allows attackers to conduct (1) SQL injection attacks via an attachment name that is not properly handled by inc/functions_upload.php (CVE-2005-4602), and possibly (2) other attacks related to threadmode in usercp.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://community.mybboard.net/showthread.php?tid=5960" source="CONFIRM" patch="1">http://community.mybboard.net/showthread.php?tid=5960</ref>
      <ref url="http://www.securityfocus.com/bid/16230" source="BID">16230</ref>
      <ref url="http://community.mybboard.net/showthread.php?tid=5853&amp;pid=35151#pid35151" source="MISC">http://community.mybboard.net/showthread.php?tid=5853&amp;pid=35151#pid35151</ref>
      <ref url="http://community.mybboard.net/showthread.php?tid=5853&amp;pid=35088#pid35088" source="MISC">http://community.mybboard.net/showthread.php?tid=5853&amp;pid=35088#pid35088</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24115" source="XF">mybb-usercp-script-sql-injection(24115)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mybulletinboard" name="mybulletinboard">
        <vers num="1.0.2"/>
        <vers num="1.01"/>
        <vers num="1.0_final"/>
        <vers num="1.0_preview_release_2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0220" published="2006-01-16" name="CVE-2006-0220" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal 5.3 through 6.1.1 allow remote attackers to inject arbitrary web script or HTML via (1) the day parameter in calendar.php and (2) the input form in search.php.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  It is possible that this issue is resultant from an SQL injection problem in CVE-2005-4227.3 and CVE-2005-4227.13.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16232" source="BID">16232</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421914/100/0/threaded" source="BUGTRAQ">20060113 DCP Portal Cross-Site Scripting Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24153" source="XF">dcpportal-calendar-search-xss(24153)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="codeworx_technologies" name="dcp-portal">
        <vers num="5.3"/>
        <vers num="5.3.1"/>
        <vers num="5.3.2"/>
        <vers num="6.0"/>
        <vers num="6.1"/>
        <vers num="6.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0221" published="2006-01-16" name="CVE-2006-0221" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.asp in the Admin Panel in Dragon Design Services Network (DDSN) cm3 content manager (CM3CMS) allows remote attackers to execute arbitrary SQL commands via the (1) username or (2) password.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24266" source="XF">cm3-login-sql-injection(24266)</ref>
      <ref url="http://www.securityfocus.com/bid/16231" source="BID">16231</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421941/100/0/threaded" source="BUGTRAQ">20060113 DDSN CMS Admin Panel SQL Injection Vulnerability</ref>
      <ref url="http://www.osvdb.org/22696" source="OSVDB">22696</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ddsn" name="cm3cms">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0222" published="2006-01-16" name="CVE-2006-0222" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in fullview.php in AlstraSoft Template Seller Pro allows remote attackers to inject arbitrary web script or HTML via the tempid parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24235" source="XF">template-seller-fullview-xss(24235)</ref>
      <ref url="http://www.securityfocus.com/bid/16233" source="BID">16233</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421916/100/0/threaded" source="BUGTRAQ">20060113 AlstraSoft Template Seller Pro Cross-Site Scripting Vulnerability</ref>
      <ref url="http://www.osvdb.org/22746" source="OSVDB">22746</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alstrasoft" name="template_seller">
        <vers num="" edition=":pro"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0223" published="2006-01-16" name="CVE-2006-0223" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Shanghai TopCMM 123 Flash Chat Server Software 5.1 allows attackers to create or overwrite arbitrary files on the server via ".." (dot dot) sequences in the username field.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16235" source="BID" patch="1">16235</ref>
      <ref url="http://www.123flashchat.com/flash-chat-server-v512.html" source="MISC" patch="1">http://www.123flashchat.com/flash-chat-server-v512.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24137" source="XF">123flashchat-user-directory-traversal(24137)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0198" source="VUPEN" adv="1">ADV-2006-0198</ref>
      <ref url="http://www.osvdb.org/22440" source="OSVDB">22440</ref>
      <ref url="http://secunia.com/advisories/18455" source="SECUNIA" adv="1">18455</ref>
    </refs>
    <vuln_soft>
      <prod vendor="topcmm_computing" name="123_flash_chat_server">
        <vers num="5.0"/>
        <vers num="5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0224" published="2006-01-24" name="CVE-2006-0224" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in Library of Assorted Spiffy Things (LibAST) 0.6.1 and earlier, as used in Eterm and possibly other software, allows local users to execute arbitrary code as the utmp user via a long -X command line argument (alternative configuration file name).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423207/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20060123 [ Rosiello Security ] Eterm-LibAST Advisory</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423088/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20060125 Rosiello Security - Eterm-LibAST Advisory</ref>
      <ref url="http://www.rosiello.org/en/read_bugs.php?id=25" source="MISC" patch="1" adv="1">http://www.rosiello.org/en/read_bugs.php?id=25</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0314" source="VUPEN">ADV-2006-0314</ref>
      <ref url="http://www.securityfocus.com/bid/16350" source="BID">16350</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423366/100/0/threaded" source="BUGTRAQ">20060123 LibAST 0.7 Release Fixes Security Vulnerability</ref>
      <ref url="http://freshmeat.net/projects/libast/?branch_id=17907&amp;release_id=217840" source="CONFIRM">http://freshmeat.net/projects/libast/?branch_id=17907&amp;release_id=217840</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24303" source="XF">eterm-libast-filename-bo(24303)</ref>
      <ref url="http://www.osvdb.org/22735" source="OSVDB">22735</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:029" source="MANDRIVA">MDKSA-2006:029</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200601-14.xml" source="GENTOO">GLSA-200601-14</ref>
      <ref url="http://www.debian.org/security/2006/dsa-976" source="DEBIAN">DSA-976</ref>
      <ref url="http://securityreason.com/securityalert/373" source="SREASON">373</ref>
      <ref url="http://secunia.com/advisories/18916" source="SECUNIA">18916</ref>
      <ref url="http://secunia.com/advisories/18632" source="SECUNIA">18632</ref>
      <ref url="http://secunia.com/advisories/18586" source="SECUNIA">18586</ref>
    </refs>
    <vuln_soft>
      <prod vendor="libast" name="libast">
        <vers num="0.4"/>
        <vers num="0.5"/>
        <vers num="0.6"/>
        <vers num="0.6.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0225" published="2006-01-25" name="CVE-2006-0225" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">scp in OpenSSH 4.2p1 allows attackers to execute arbitrary commands via filenames that contain shell metacharacters or spaces, which are expanded twice.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" source="CERT">TA07-072A</ref>
      <ref url="http://secunia.com/advisories/18595" source="SECUNIA" patch="1" adv="1">18595</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=174026" source="CONFIRM">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=174026</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24305" source="XF">openssh-scp-command-execution(24305)</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/2120" source="VUPEN">ADV-2007-2120</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0930" source="VUPEN">ADV-2007-0930</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/4869" source="VUPEN">ADV-2006-4869</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/2490" source="VUPEN">ADV-2006-2490</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0306" source="VUPEN">ADV-2006-0306</ref>
      <ref url="http://www.ubuntu.com/usn/usn-255-1" source="UBUNTU">USN-255-1</ref>
      <ref url="http://www.trustix.org/errata/2006/0004" source="TRUSTIX">2006-0004</ref>
      <ref url="http://www.securityfocus.com/bid/16369" source="BID">16369</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425397/100/0/threaded" source="FEDORA">FLSA-2006:168935</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0044.html" source="REDHAT">RHSA-2006:0044</ref>
      <ref url="http://www.osvdb.org/22692" source="OSVDB">22692</ref>
      <ref url="http://www.openpkg.org/security/OpenPKG-SA-2006.003-openssh.html" source="OPENPKG">OpenPKG-SA-2006.003</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_08_openssh.html" source="SUSE">SUSE-SA:2006:008</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200602-11.xml" source="GENTOO">GLSA-200602-11</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.425802" source="SLACKWARE">SSA:2006-045-06</ref>
      <ref url="http://securitytracker.com/id?1015540" source="SECTRACK">1015540</ref>
      <ref url="http://secunia.com/advisories/19159" source="SECUNIA">19159</ref>
      <ref url="http://secunia.com/advisories/18970" source="SECUNIA">18970</ref>
      <ref url="http://secunia.com/advisories/18969" source="SECUNIA">18969</ref>
      <ref url="http://secunia.com/advisories/18964" source="SECUNIA">18964</ref>
      <ref url="http://secunia.com/advisories/18910" source="SECUNIA">18910</ref>
      <ref url="http://secunia.com/advisories/18850" source="SECUNIA">18850</ref>
      <ref url="http://secunia.com/advisories/18798" source="SECUNIA">18798</ref>
      <ref url="http://secunia.com/advisories/18736" source="SECUNIA">18736</ref>
      <ref url="http://secunia.com/advisories/18650" source="SECUNIA">18650</ref>
      <ref url="http://secunia.com/advisories/18579" source="SECUNIA">18579</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9962" source="OVAL">oval:org.mitre.oval:def:9962</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=c00815112" source="HP">HPSBUX02178</ref>
      <ref url="ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.8/common/005_ssh.patch" source="OPENBSD">20060212 [3.8] 005: SECURITY FIX: February 12, 2006</ref>
      <ref url="http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&amp;ID=2751" source="CONFIRM">http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&amp;ID=2751</ref>
      <ref url="http://www14.software.ibm.com/webapp/set2/sas/f/hmc/power5/install/v52.Readme.html#MH00688" source="CONFIRM">http://www14.software.ibm.com/webapp/set2/sas/f/hmc/power5/install/v52.Readme.html#MH00688</ref>
      <ref url="http://www.vmware.com/support/vi3/doc/esx-9986131-patch.html" source="CONFIRM">http://www.vmware.com/support/vi3/doc/esx-9986131-patch.html</ref>
      <ref url="http://www.vmware.com/support/vi3/doc/esx-3069097-patch.html" source="CONFIRM">http://www.vmware.com/support/vi3/doc/esx-3069097-patch.html</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0698.html" source="REDHAT">RHSA-2006:0698</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0298.html" source="REDHAT">RHSA-2006:0298</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:034" source="MANDRIVA">MDKSA-2006:034</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2007-246.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2007-246.htm</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-262.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-262.htm</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-174.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-174.htm</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-158.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-158.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102961-1" source="SUNALERT">102961</ref>
      <ref url="http://securityreason.com/securityalert/462" source="SREASON">462</ref>
      <ref url="http://secunia.com/advisories/25936" source="SECUNIA">25936</ref>
      <ref url="http://secunia.com/advisories/25607" source="SECUNIA">25607</ref>
      <ref url="http://secunia.com/advisories/24479" source="SECUNIA">24479</ref>
      <ref url="http://secunia.com/advisories/23680" source="SECUNIA">23680</ref>
      <ref url="http://secunia.com/advisories/23340" source="SECUNIA">23340</ref>
      <ref url="http://secunia.com/advisories/23241" source="SECUNIA">23241</ref>
      <ref url="http://secunia.com/advisories/22196" source="SECUNIA">22196</ref>
      <ref url="http://secunia.com/advisories/21724" source="SECUNIA">21724</ref>
      <ref url="http://secunia.com/advisories/21492" source="SECUNIA">21492</ref>
      <ref url="http://secunia.com/advisories/21262" source="SECUNIA">21262</ref>
      <ref url="http://secunia.com/advisories/21129" source="SECUNIA">21129</ref>
      <ref url="http://secunia.com/advisories/20723" source="SECUNIA">20723</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html" source="APPLE">APPLE-SA-2007-03-13</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=c00815112" source="HP">HPSBUX02178</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305214" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305214</ref>
      <ref url="http://blogs.sun.com/security/entry/sun_alert_102961_security_vulnerability" source="CONFIRM">http://blogs.sun.com/security/entry/sun_alert_102961_security_vulnerability</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060703-01-U.asc" source="SGI">20060703-01-P</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1138" source="OVAL" sig="1">oval:org.mitre.oval:def:1138</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openssh">
        <vers num="3.0"/>
        <vers num="3.0.1"/>
        <vers num="3.0.1p1"/>
        <vers num="3.0.2"/>
        <vers num="3.0.2p1"/>
        <vers num="3.0p1"/>
        <vers num="3.1"/>
        <vers num="3.1p1"/>
        <vers num="3.2"/>
        <vers num="3.2.2p1"/>
        <vers num="3.2.3p1"/>
        <vers num="3.3"/>
        <vers num="3.3p1"/>
        <vers num="3.4"/>
        <vers num="3.4p1"/>
        <vers num="3.5"/>
        <vers num="3.5p1"/>
        <vers num="3.6"/>
        <vers num="3.6.1"/>
        <vers num="3.6.1p1"/>
        <vers num="3.6.1p2"/>
        <vers num="3.7"/>
        <vers num="3.7.1"/>
        <vers num="3.7.1p2"/>
        <vers num="3.8"/>
        <vers num="3.8.1"/>
        <vers num="3.8.1p1"/>
        <vers num="3.9"/>
        <vers num="3.9.1"/>
        <vers num="3.9.1p1"/>
        <vers num="4.0p1"/>
        <vers num="4.1p1"/>
        <vers num="4.2p1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0226" published="2006-01-18" name="CVE-2006-0226" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Integer overflow in IEEE 802.11 network subsystem (ieee80211_ioctl.c) in FreeBSD before 6.0-STABLE, while scanning for wireless networks, allows remote attackers to execute arbitrary code by broadcasting crafted (1) beacon or (2) probe response frames.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16296" source="BID" patch="1">16296</ref>
      <ref url="http://secunia.com/advisories/18353" source="SECUNIA" patch="1" adv="1">18353</ref>
      <ref url="http://www.signedness.org/advisories/sps-0x1.txt" source="MISC" adv="1">http://www.signedness.org/advisories/sps-0x1.txt</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:05.80211.asc" source="FREEBSD">FreeBSD-SA-06:05</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24192" source="XF">bsd-ieee80211-bo(24192)</ref>
      <ref url="http://www.osvdb.org/22537" source="OSVDB">22537</ref>
      <ref url="http://www.blackhat.com/html/bh-europe-07/bh-eu-07-speakers.html#Eriksson" source="MISC">http://www.blackhat.com/html/bh-europe-07/bh-eu-07-speakers.html#Eriksson</ref>
      <ref url="http://securitytracker.com/id?1015518" source="SECTRACK">1015518</ref>
      <ref url="http://kernelwars.blogspot.com/2007/01/alive.html" source="MISC">http://kernelwars.blogspot.com/2007/01/alive.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="6.0" edition="release"/>
        <vers num="6.0" edition="stable"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0227" published="2006-01-17" name="CVE-2006-0227" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:P)" CVSS_score="2.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="1.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in lpsched in Sun Solaris 8, 9, and 10 allow local users to delete arbitrary files or disable the LP print service via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <vuln_types>
      <race/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102033-1" source="SUNALERT" patch="1">102033</ref>
      <ref url="http://securitytracker.com/id?1015492" source="SECTRACK" patch="1">1015492</ref>
      <ref url="http://secunia.com/advisories/18498" source="SECUNIA" patch="1" adv="1">18498</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0200" source="VUPEN">ADV-2006-0200</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24127" source="XF">solaris-lpsched-dos(24127)</ref>
      <ref url="http://www.securityfocus.com/bid/16245" source="BID">16245</ref>
      <ref url="http://www.osvdb.org/22442" source="OSVDB">22442</ref>
      <ref url="http://www.osvdb.org/22441" source="OSVDB">22441</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-056.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-056.htm</ref>
      <ref url="http://secunia.com/advisories/19087" source="SECUNIA">19087</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:662" source="OVAL" sig="1">oval:org.mitre.oval:def:662</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="10.0" edition=""/>
        <vers num="10.0" edition=":sparc"/>
        <vers num="10.0" edition=":x86"/>
        <vers num="8.1"/>
        <vers num="8.2"/>
        <vers num="9.0" edition=""/>
        <vers num="9.0" edition=":sparc"/>
        <vers num="9.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0228" published="2006-01-17" name="CVE-2006-0228" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The RBAC functionality in grsecurity before 2.1.8 does not properly handle when the admin role creates a service and then exits the shell without unauthenticating, which causes the service to be restarted with the admin role still active.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16261" source="BID" patch="1">16261</ref>
      <ref url="http://secunia.com/advisories/18458" source="SECUNIA" patch="1" adv="1">18458</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0199" source="VUPEN">ADV-2006-0199</ref>
      <ref url="http://www.grsecurity.org/news.php#grsec218" source="CONFIRM">http://www.grsecurity.org/news.php#grsec218</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24156" source="XF">grsecurity-rbac-admin-privileges(24156)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="grsecurity" name="grsecurity_kernel_patch">
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.1.0"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.1.3"/>
        <vers num="2.1.4"/>
        <vers num="2.1.5"/>
        <vers num="2.1.6"/>
        <vers num="2.1.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0229" published="2006-01-17" name="CVE-2006-0229" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Unquoted Windows search path vulnerability in Wehntrust might allow local users to gain privileges via a malicious "program.exe" file in the C: folder, which is run when Wehntrust creates the autostart key.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/422046/100/0/threaded" source="BUGTRAQ" patch="1">20060116 Re: [Full-disclosure] WehnTrust - When you have to trust Wehntrust</ref>
      <ref url="http://www.securityfocus.com/bid/16268" source="BID">16268</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422020/100/0/threaded" source="BUGTRAQ">20060116 WehnTrust - When you have to trust Wehntrust</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24315" source="XF">wehntrust-service-start-file-execution(24315)</ref>
      <ref url="http://www.wehnus.com/downloads.pl" source="MISC">http://www.wehnus.com/downloads.pl</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wehnus" name="wehntrust">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0230" published="2006-04-24" name="CVE-2006-0230" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Symantec Scan Engine 5.0.0.24, and possibly other versions before 5.1.0.7, uses a client-side check to verify a password, which allows remote attackers to gain administrator privileges via a modified client that sends certain XML requests.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/118388" source="CERT-VN">VU#118388</ref>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2006-q2/0010.html" source="VULNWATCH" patch="1" adv="1">20060421 Rapid7 Advisory R7-0021: Symantec Scan Engine Authentication Fundamental Design Error</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1464" source="VUPEN">ADV-2006-1464</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25972" source="XF">sse-unauth-admin-access(25972)</ref>
      <ref url="http://www.symantec.com/avcenter/security/Content/2006.04.21.html" source="CONFIRM">http://www.symantec.com/avcenter/security/Content/2006.04.21.html</ref>
      <ref url="http://www.securityfocus.com/bid/17637" source="BID">17637</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431734/100/0/threaded" source="BUGTRAQ">20060421 [Symantec Security Advisor] Symantec Scan Engine Multiple Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431724/100/0/threaded" source="BUGTRAQ">20060421 Rapid7 Advisory R7-0021: Symantec Scan Engine Authentication Fundamental Design Error</ref>
      <ref url="http://secunia.com/advisories/19734" source="SECUNIA">19734</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="antivirus_scan_engine">
        <vers num="5.0.0.24"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0231" published="2006-04-24" name="CVE-2006-0231" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Symantec Scan Engine 5.0.0.24, and possibly other versions before 5.1.0.7, uses the same private DSA key for each installation, which allows remote attackers to conduct man-in-the-middle attacks and decrypt communications.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2006-q2/0011.html" source="VULNWATCH" patch="1" adv="1">20060421 Rapid7 Advisory R7-0022: Symantec Scan Engine Known Immutable DSA Private Key</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1464" source="VUPEN">ADV-2006-1464</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25973" source="XF">sse-insecure-private-key(25973)</ref>
      <ref url="http://www.symantec.com/avcenter/security/Content/2006.04.21.html" source="CONFIRM">http://www.symantec.com/avcenter/security/Content/2006.04.21.html</ref>
      <ref url="http://www.securityfocus.com/bid/17637" source="BID">17637</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431734/100/0/threaded" source="BUGTRAQ">20060421 [Symantec Security Advisor] Symantec Scan Engine Multiple Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431725/100/0/threaded" source="BUGTRAQ">20060421 Rapid7 Advisory R7-0022: Symantec Scan Engine Known Immutable DSA Private Key</ref>
      <ref url="http://securitytracker.com/id?1015974" source="SECTRACK">1015974</ref>
      <ref url="http://secunia.com/advisories/19734" source="SECUNIA">19734</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="antivirus_scan_engine">
        <vers num="5.0.0.24"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0232" published="2006-04-24" name="CVE-2006-0232" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Symantec Scan Engine 5.0.0.24, and possibly other versions before 5.1.0.7, stores sensitive log and virus definition files under the web root with insufficient access control, which allows remote attackers to obtain the information via direct requests.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <access/>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://archives.neohapsis.com/archives/vulnwatch/2006-q2/0012.html" source="VULNWATCH" patch="1" adv="1">20060421 Rapid7 Advisory R7-0023: Symantec Scan Engine File Disclosure Vulnerability</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1464" source="VUPEN">ADV-2006-1464</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25974" source="XF">sse-unauth-file-access(25974)</ref>
      <ref url="http://www.symantec.com/avcenter/security/Content/2006.04.21.html" source="CONFIRM">http://www.symantec.com/avcenter/security/Content/2006.04.21.html</ref>
      <ref url="http://www.securityfocus.com/bid/17637" source="BID">17637</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431734/100/0/threaded" source="BUGTRAQ">20060421 [Symantec Security Advisor] Symantec Scan Engine Multiple Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/431728/100/0/threaded" source="BUGTRAQ">20060421 Rapid7 Advisory R7-0023: Symantec Scan Engine File Disclosure Vulnerability</ref>
      <ref url="http://securitytracker.com/id?1015974" source="SECTRACK">1015974</ref>
      <ref url="http://securityreason.com/securityalert/759" source="SREASON">759</ref>
      <ref url="http://securityreason.com/securityalert/758" source="SREASON">758</ref>
      <ref url="http://secunia.com/advisories/19734" source="SECUNIA">19734</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="antivirus_scan_engine">
        <vers num="5.0.0.24"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0233" published="2006-01-17" name="CVE-2006-0233" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in functions.php in microBlog 2.0 RC-10 allows remote attackers to inject arbitrary web script and HTML via a javascript: URI in a [url] BBcode tag.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24140" source="XF">microblog-functions-xss(24140)</ref>
      <ref url="http://www.securityfocus.com/bid/16272" source="BID">16272</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422145/100/0/threaded" source="BUGTRAQ" adv="1">20060117 [eVuln] microBlog BBCode XSS Vulnerability</ref>
      <ref url="http://securitytracker.com/id?1015496" source="SECTRACK">1015496</ref>
      <ref url="http://evuln.com/vulns/36/summary.html" source="MISC">http://evuln.com/vulns/36/summary.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microblog" name="microblog">
        <vers num="2.0_rc10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0234" published="2006-01-17" name="CVE-2006-0234" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in microBlog 2.0 RC-10 allows remote attackers to execute arbitrary SQL commands via the (1) month and (2) year parameters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0239" source="VUPEN">ADV-2006-0239</ref>
      <ref url="http://www.securityfocus.com/bid/16270" source="BID">16270</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422141/100/0/threaded" source="BUGTRAQ" adv="1">20060117 [eVuln] microBlog SQL Injection Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24132" source="XF">microblog-index-sql-injection(24132)</ref>
      <ref url="http://www.osvdb.org/22512" source="OSVDB">22512</ref>
      <ref url="http://securitytracker.com/id?1015496" source="SECTRACK">1015496</ref>
      <ref url="http://secunia.com/advisories/18442" source="SECUNIA">18442</ref>
      <ref url="http://evuln.com/vulns/35/summary.html" source="MISC">http://evuln.com/vulns/35/summary.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microblog" name="microblog">
        <vers num="2.0_rc10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0235" published="2006-01-17" name="CVE-2006-0235" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in WhiteAlbum 2.5 allows remote attackers to execute arbitrary SQL commands via the dir parameter to pictures.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0241" source="VUPEN">ADV-2006-0241</ref>
      <ref url="http://www.securityfocus.com/bid/16247" source="BID">16247</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422105/100/0/threaded" source="BUGTRAQ" adv="1">20060116 White Album Sql &amp;#304;njection biyosecurity.be</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24271" source="XF">whitealbum-pictures-sql-injection(24271)</ref>
      <ref url="http://www.osvdb.org/22520" source="OSVDB">22520</ref>
      <ref url="http://www.biyosecurity.be/bugs/whitealbum.txt" source="MISC">http://www.biyosecurity.be/bugs/whitealbum.txt</ref>
      <ref url="http://secunia.com/advisories/18460" source="SECUNIA">18460</ref>
    </refs>
    <vuln_soft>
      <prod vendor="white_angle" name="white_album">
        <vers num="2.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0236" published="2006-01-17" name="CVE-2006-0236" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">GUI display truncation vulnerability in Mozilla Thunderbird 1.0.2, 1.0.6, and 1.0.7 allows user-assisted attackers to execute arbitrary code via an attachment with a filename containing a large number of spaces ending with a dangerous extension that is not displayed by Thunderbird, along with an inconsistent Content-Type header, which could be used to trick a user into downloading dangerous content by dragging or saving the attachment.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16271" source="BID" patch="1">16271</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422148/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20060117 Secunia Research: Mozilla Thunderbird Attachment SpoofingVulnerability</ref>
      <ref url="http://secunia.com/secunia_research/2005-22/advisory" source="MISC" patch="1" adv="1">http://secunia.com/secunia_research/2005-22/advisory</ref>
      <ref url="http://secunia.com/advisories/15907" source="SECUNIA" patch="1" adv="1">15907</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=300246" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=300246</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24164" source="XF">thunderbird-attachment-ext-spoofing(24164)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0230" source="VUPEN" adv="1">ADV-2006-0230</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:021" source="MANDRIVA">MDKSA-2006:021</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.5" edition="beta2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0237" published="2006-01-17" name="CVE-2006-0237" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in GTP iCommerce allows remote attackers to inject arbitrary web script or HTML via the (1) cat and (2) subcat parameters.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0214" source="VUPEN">ADV-2006-0214</ref>
      <ref url="http://www.securityfocus.com/bid/16255" source="BID">16255</ref>
      <ref url="http://secunia.com/advisories/18470" source="SECUNIA" adv="1">18470</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24150" source="XF">gtpicommerce-index-xss(24150)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gtp" name="icommerce">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0238" published="2006-01-17" name="CVE-2006-0238" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in wp-stats.php in GaMerZ WP-Stats 2.0 allows remote attackers to execute arbitrary SQL commands via the author parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.lesterchan.net/blogs/" source="CONFIRM" patch="1">http://www.lesterchan.net/blogs/</ref>
      <ref url="http://secunia.com/advisories/18471" source="SECUNIA" patch="1" adv="1">18471</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0192" source="VUPEN">ADV-2006-0192</ref>
      <ref url="http://www.securityfocus.com/bid/16241" source="BID">16241</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24163" source="XF">wpstats-script-sql-injection(24163)</ref>
      <ref url="http://www.osvdb.org/22450" source="OSVDB">22450</ref>
      <ref url="http://www.lesterchan.net/blogs/archives/2006/01/18/wp-stats-sql-injection-vulnerability" source="CONFIRM">http://www.lesterchan.net/blogs/archives/2006/01/18/wp-stats-sql-injection-vulnerability</ref>
      <ref url="http://osvdb.org/ref/22/22450-wpstats.txt" source="MISC">http://osvdb.org/ref/22/22450-wpstats.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gamerz" name="wp-stats">
        <vers prev="1" num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0239" published="2006-01-17" name="CVE-2006-0239" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Simple Blog 2.1 allow remote attackers to inject arbitrary web script or HTML via (1) a comment to comments.asp and (2) possibly certain other fields in unspecified scripts.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0194" source="VUPEN">ADV-2006-0194</ref>
      <ref url="http://www.securityfocus.com/bid/16243" source="BID">16243</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422102/100/0/threaded" source="BUGTRAQ">20060114 [HSC Security Group] Multiple SQL injection/XSS in SimpleBlog 2.1</ref>
      <ref url="http://secunia.com/advisories/18488" source="SECUNIA" adv="1">18488</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24154" source="XF">simpleblog-comment-xss(24154)</ref>
      <ref url="http://www.osvdb.org/22448" source="OSVDB">22448</ref>
      <ref url="http://www.hackerscenter.com/archive/view.asp?id=21926" source="MISC">http://www.hackerscenter.com/archive/view.asp?id=21926</ref>
    </refs>
    <vuln_soft>
      <prod vendor="8pixel.net" name="simple_blog">
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0240" published="2006-01-17" name="CVE-2006-0240" modified="2011-09-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Simple Blog 2.1 allow remote attackers to execute arbitrary SQL commands via the month parameter in an archives view operation and possibly certain other parameters in unspecified scripts.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24155" source="XF">simpleblog-month-sql-injection(24155)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0194" source="VUPEN" adv="1">ADV-2006-0194</ref>
      <ref url="http://www.securityfocus.com/bid/16243" source="BID">16243</ref>
      <ref url="http://www.securityfocus.com/archive/1/422102/100/0/threaded" source="BUGTRAQ" adv="1">20060114 [HSC Security Group] Multiple SQL injection/XSS in SimpleBlog 2.1</ref>
      <ref url="http://www.osvdb.org/22447" source="OSVDB">22447</ref>
      <ref url="http://www.hackerscenter.com/archive/view.asp?id=21926" source="MISC">http://www.hackerscenter.com/archive/view.asp?id=21926</ref>
      <ref url="http://secunia.com/advisories/18488" source="SECUNIA" adv="1">18488</ref>
    </refs>
    <vuln_soft>
      <prod vendor="8pixel.net" name="simple_blog">
        <vers prev="1" num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0241" published="2006-01-17" name="CVE-2006-0241" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability in WBNews 1.1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the Name field.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0237" source="VUPEN">ADV-2006-0237</ref>
      <ref url="http://www.securityfocus.com/bid/16277" source="BID">16277</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422133/100/0/threaded" source="BUGTRAQ">20060117 XSS in WBNews &lt; = v1.1.0</ref>
      <ref url="http://secunia.com/advisories/18499" source="SECUNIA">18499</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webmobo" name="wbnews">
        <vers num="1.1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0242" published="2006-01-17" name="CVE-2006-0242" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Cross-site scripting vulnerability in index.php in PHP Fusebox 4.0.6 allows remote attackers to inject arbitrary web script or HTML via the fuseaction parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422124/100/0/threaded" source="BUGTRAQ" patch="1">20060117 IndonesiaHack Advisory HTML injection in PHP Fusebox</ref>
      <ref url="http://www.securityfocus.com/bid/16274" source="BID">16274</ref>
      <ref url="http://securityreason.com/securityalert/355" source="SREASON">355</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_fusebox" name="php_fusebox">
        <vers num="4.0.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0243" published="2006-01-17" name="CVE-2006-0243" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in SMBCMS 2.1 allows remote attackers to inject arbitrary web script or HTML via the text parameter, which is used by the "Search Site" field.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0229" source="VUPEN">ADV-2006-0229</ref>
      <ref url="http://www.securityfocus.com/bid/16281" source="BID">16281</ref>
      <ref url="http://secunia.com/advisories/18454" source="SECUNIA" adv="1">18454</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24187" source="XF">smbcms-sitesearch-xss(24187)</ref>
      <ref url="http://www.osvdb.org/22494" source="OSVDB">22494</ref>
    </refs>
    <vuln_soft>
      <prod vendor="smbcms" name="smbcms">
        <vers num="2.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0244" published="2006-01-17" name="CVE-2006-0244" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">** DISPUTED ** Directory traversal vulnerability in workspaces.php in phpXplorer 0.9.33 allows remote attackers to include arbitrary files via a .. (dot dot) and trailing null byte (%00) in the sShare parameter.  NOTE: a followup post claims that this is not a vulnerability since the functionality of phpXplorer supports the upload of PHP files, which would not cross privilege boundaries since the PHP functionality would support read access outside the web root.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0232" source="VUPEN">ADV-2006-0232</ref>
      <ref url="http://www.securityfocus.com/bid/16263" source="BID">16263</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422158/100/0/threaded" source="BUGTRAQ">20060116 Re: Directory traversal in phpXplorer</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421997/100/0/threaded" source="BUGTRAQ" adv="1">20060116 Directory traversal in phpXplorer</ref>
      <ref url="http://www.arrelnet.com/advisories/adv20060116.html" source="MISC" adv="1">http://www.arrelnet.com/advisories/adv20060116.html</ref>
      <ref url="http://secunia.com/advisories/18518" source="SECUNIA" adv="1">18518</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/39982" source="XF">phpxplorer-sshare-directory-traversal(39982)</ref>
      <ref url="http://securityreason.com/securityalert/353" source="SREASON">353</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpxplorer" name="phpxplorer">
        <vers num="0.9.33"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0245" published="2006-01-17" name="CVE-2006-0245" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in CubeCart 3.0.7-pl1 allow remote attackers to inject arbitrary web script or HTML via the (3) redir, (4) productId, (5) docId, (6) act, and (7) catId parameters in index.php; and the (8) username field in a login action in index.php.  NOTE: the cart.php/redir and index.php/searchStr vectors are already covered by CVE-2005-3152.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0227" source="VUPEN">ADV-2006-0227</ref>
      <ref url="http://www.securityfocus.com/bid/16259" source="BID">16259</ref>
      <ref url="http://www.osvdb.org/22471" source="OSVDB">22471</ref>
      <ref url="http://secunia.com/advisories/18519" source="SECUNIA" adv="1">18519</ref>
      <ref url="http://lostmon.blogspot.com/2006/01/cubecart-307-pl1-indexphp-multiple.html" source="MISC" adv="1">http://lostmon.blogspot.com/2006/01/cubecart-307-pl1-indexphp-multiple.html</ref>
      <ref url="http://bugs.cubecart.com/?do=details&amp;id=459" source="MISC" adv="1">http://bugs.cubecart.com/?do=details&amp;id=459</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24177" source="XF">cubecart-index-script-xss(24177)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="devellion" name="cubecart">
        <vers num="3.0.7-pl1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0246" published="2006-01-17" name="CVE-2006-0246" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in down.pl in Widexl Download Tracker 1.06 allows remote attackers to inject arbitrary web script or HTML via the ID parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0213" source="VUPEN">ADV-2006-0213</ref>
      <ref url="http://www.securityfocus.com/bid/16265" source="BID">16265</ref>
      <ref url="http://www.osvdb.org/22462" source="OSVDB">22462</ref>
      <ref url="http://secunia.com/advisories/18472" source="SECUNIA" adv="1">18472</ref>
      <ref url="http://osvdb.org/ref/22/22462-widexl.txt" source="MISC">http://osvdb.org/ref/22/22462-widexl.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24161" source="XF">downloadtracker-down-xss(24161)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="widexl" name="download_tracker">
        <vers num="1.0.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0247" published="2006-01-17" name="CVE-2006-0247" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in anyboard.cgi in Netbula Anyboard 9.9 and earlier allows remote attackers to inject arbitrary web script or HTML via the tK parameter in a find command.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0188" source="VUPEN">ADV-2006-0188</ref>
      <ref url="http://www.securityfocus.com/bid/16264" source="BID">16264</ref>
      <ref url="http://www.osvdb.org/22461" source="OSVDB">22461</ref>
      <ref url="http://secunia.com/advisories/18469" source="SECUNIA" adv="1">18469</ref>
      <ref url="http://osvdb.org/ref/22/22461-anyboard.txt" source="MISC">http://osvdb.org/ref/22/22461-anyboard.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24167" source="XF">netbula-anyboard-script-xss(24167)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netbula" name="anyboard">
        <vers prev="1" num="9.9.5.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0248" published="2006-01-17" name="CVE-2006-0248" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Virata-EmWeb web server 6_1_0, as used in (1) Intracom JetSpeed 500 and 520 and (2) Allied Data Technologies CopperJet 811 RouterPlus, allows remote attackers to access privileged information, such as user lists and configuration settings, via direct HTTP requests.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0218" source="VUPEN">ADV-2006-0218</ref>
      <ref url="http://secunia.com/advisories/18483" source="SECUNIA" adv="1">18483</ref>
      <ref url="http://blog.globalnetworks.gr/?p=4" source="MISC">http://blog.globalnetworks.gr/?p=4</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24304" source="XF">virata-emweb-unauth-access(24304)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="intracom" name="jetspeed">
        <vers num="500"/>
        <vers num="520"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0249" published="2006-01-17" name="CVE-2006-0249" modified="2011-08-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in viewcat.php in BitDamaged geoBlog MOD_1.0 allows remote attackers to execute arbitrary SQL commands, then steal credentials and upload files, via the cat parameter ($tmpCategory variable).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24146" source="XF">geoBlog-viewcat-sql-injection(24146)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0191" source="VUPEN" adv="1">ADV-2006-0191</ref>
      <ref url="http://www.securityfocus.com/bid/16249" source="BID">16249</ref>
      <ref url="http://www.osvdb.org/22463" source="OSVDB">22463</ref>
      <ref url="http://securitytracker.com/id?1015493" source="SECTRACK">1015493</ref>
      <ref url="http://secunia.com/advisories/18504" source="SECUNIA" adv="1">18504</ref>
      <ref url="http://evuln.com/vulns/33/summary.html" source="MISC">http://evuln.com/vulns/33/summary.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bitdamaged" name="geoblog">
        <vers num="mod_1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0250" published="2006-01-17" name="CVE-2006-0250" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Format string vulnerability in the snmp_input function in snmptrapd in CMU SNMP utilities (cmu-snmp) allows remote attackers to execute arbitrary code by sending crafted SNMP messages to UDP port 162.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0234" source="VUPEN">ADV-2006-0234</ref>
      <ref url="http://www.securityfocus.com/bid/16267" source="BID">16267</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422086/100/0/threaded" source="BUGTRAQ">20060116 Digital Armaments Security Advisory 01.16.2006: CMU SNMP utilities snmptrad Format String Vulnerability</ref>
      <ref url="http://www.digitalarmaments.com/2006040164883273.html" source="MISC">http://www.digitalarmaments.com/2006040164883273.html</ref>
      <ref url="http://secunia.com/advisories/18525" source="SECUNIA" adv="1">18525</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24178" source="XF">cmusnmp-snmpinput-format-string(24178)</ref>
      <ref url="http://www.osvdb.org/22493" source="OSVDB">22493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="carnegie_mellon_university" name="snmptrapd">
        <vers num="3.6"/>
        <vers num="3.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0251" published="2006-01-17" name="CVE-2006-0251" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in fom.cgi in Faq-O-Matic 2.711 allows remote attackers to inject arbitrary web script or HTML via the (1) _duration, (2) file, and (3) cmd parameters.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0189" source="VUPEN">ADV-2006-0189</ref>
      <ref url="http://www.securityfocus.com/bid/16251" source="BID">16251</ref>
      <ref url="http://www.osvdb.org/22439" source="OSVDB">22439</ref>
      <ref url="http://secunia.com/advisories/18468" source="SECUNIA" adv="1">18468</ref>
      <ref url="http://osvdb.org/ref/22/22439-faqomatic.txt" source="MISC">http://osvdb.org/ref/22/22439-faqomatic.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24165" source="XF">faqomatic-fom-xss(24165)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="faq-o-matic" name="faq-o-matic">
        <vers prev="1" num="2.711"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0252" published="2006-01-17" name="CVE-2006-0252" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in Benders Calendar 1.0 allows remote attackers to execute arbitrary SQL commands via multiple parameters, as demonstrated by the (1) year, (2) month, and (3) day parameters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0190" source="VUPEN">ADV-2006-0190</ref>
      <ref url="http://www.securityfocus.com/bid/16242" source="BID" adv="1">16242</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422052/100/0/threaded" source="BUGTRAQ" adv="1">20060115 [eVuln] Benders Calendar SQL Injection</ref>
      <ref url="http://www.osvdb.org/22449" source="OSVDB">22449</ref>
      <ref url="http://securitytracker.com/id?1015491" source="SECTRACK" adv="1">1015491</ref>
      <ref url="http://secunia.com/advisories/18462" source="SECUNIA" adv="1">18462</ref>
      <ref url="http://evuln.com/vulns/30/summary.html" source="MISC" adv="1">http://evuln.com/vulns/30/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24120" source="XF">benderscalendar-sql-injection(24120)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="benders_calendar" name="benders_calendar">
        <vers prev="1" num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0253" published="2006-01-17" name="CVE-2006-0253" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Buffer overflow in the Bluetooth OBEX Object Push service in "Blue Neighbors.EXE" in AmbiCom Blue Neighbors 2.50 Build 2500 and earlier allows remote attackers to execute arbitrary code via a long file name, as demonstrated via a long RFILE argument to ussp-push.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0219" source="VUPEN">ADV-2006-0219</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422481/100/0/threaded" source="BUGTRAQ">20060120 DMA[2006-0115a] - 'AmbiCom Bluetooth Object Push Overflow'</ref>
      <ref url="http://www.digitalmunition.com/DMA%5B2006-0115a%5D.txt" source="MISC">http://www.digitalmunition.com/DMA%5B2006-0115a%5D.txt</ref>
      <ref url="http://secunia.com/advisories/18466" source="SECUNIA" adv="1">18466</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24179" source="XF">ambicom-bluetooth-objectpush-bo(24179)</ref>
      <ref url="http://www.securityfocus.com/bid/16258" source="BID">16258</ref>
      <ref url="http://securityreason.com/securityalert/366" source="SREASON">366</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ambicom" name="blue_neighbors">
        <vers num="2.50_build_2500"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0254" published="2006-01-17" name="CVE-2006-0254" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Apache Geronimo 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) time parameter to cal2.jsp and (2) any invalid parameter, which causes an XSS when the log file is viewed by the Web-Access-Log viewer.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://issues.apache.org/jira/secure/ReleaseNote.jspa?version=12310181&amp;styleName=Html&amp;projectId=10220&amp;Create=Create" source="CONFIRM">https://issues.apache.org/jira/secure/ReleaseNote.jspa?version=12310181&amp;styleName=Html&amp;projectId=10220&amp;Create=Create</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0217" source="VUPEN">ADV-2006-0217</ref>
      <ref url="http://www.securityfocus.com/bid/16260" source="BID">16260</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421996/100/0/threaded" source="BUGTRAQ" adv="1">20060115 Apache Geronimo 1.0 - CSS and persistent HTML-Injectionvulnerabilities</ref>
      <ref url="http://www.oliverkarow.de/research/geronimo_css.txt" source="MISC" adv="1">http://www.oliverkarow.de/research/geronimo_css.txt</ref>
      <ref url="http://secunia.com/advisories/18485" source="SECUNIA" adv="1">18485</ref>
      <ref url="http://issues.apache.org/jira/browse/GERONIMO-1474" source="MISC" adv="1">http://issues.apache.org/jira/browse/GERONIMO-1474</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24159" source="XF">geronimo-webaccesslog-viewer-xss(24159)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24158" source="XF">geronimo-jspexamples-xss(24158)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2008-0261.html" source="REDHAT">RHSA-2008:0261</ref>
      <ref url="http://secunia.com/advisories/31493" source="SECUNIA">31493</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2008-0630.html" source="REDHAT">RHSA-2008:0630</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="geronimo">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0255" published="2006-01-17" name="CVE-2006-0255" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unquoted Windows search path vulnerability in Check Point VPN-1 SecureClient might allow local users to gain privileges via a malicious "program.exe" file in the C: folder, which is run when SecureClient attempts to launch the Sr_GUI.exe program.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0258" source="VUPEN">ADV-2006-0258</ref>
      <ref url="http://www.securityfocus.com/bid/16290" source="BID">16290</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422263/100/0/threaded" source="BUGTRAQ">20060117 [ TZO-012006 ] Checkpoint VPN-1 SecureClient insecure usage of CreateProcess()</ref>
      <ref url="http://secdev.zoller.lu/research/checkpoint.txt" source="MISC">http://secdev.zoller.lu/research/checkpoint.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="checkpoint" name="vpn-1">
        <vers num="" edition=":fp1"/>
        <vers num="4.1" edition="sp1"/>
        <vers num="4.1" edition="sp2"/>
        <vers num="4.1" edition="sp3"/>
        <vers num="4.1" edition="sp4"/>
        <vers num="4.1" edition="sp5"/>
        <vers num="4.1" edition="sp5a"/>
        <vers num="4.1" edition="sp6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0256" published="2006-01-18" name="CVE-2006-0256" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Advanced Queuing component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.2.0.6, 10.1.0.3 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB01.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN">VU#545804</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" adv="1">18608</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.3"/>
        <vers num="8.1.7.4"/>
        <vers num="9.0.1.5"/>
        <vers num="9.2.0.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0257" published="2006-01-18" name="CVE-2006-0257" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Change Data Capture component of Oracle Database server 9.2.0.7, 10.1.0.5, and 10.2.0.1 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB02.  NOTE: details are unavailable from Oracle, but they have not publicly disputed a claim by a reliable independent researcher that states that the problem is SQL injection in the CDC_ALLOCATE_LOCK function of the DBMS_CDC_UTILITY package.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN" adv="1">VU#545804</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK" patch="1" adv="1">1015499</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN" adv="1">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN" adv="1">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://www.osvdb.org/22540" source="OSVDB">22540</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" adv="1">18608</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.5"/>
        <vers num="10.2.0.1"/>
        <vers num="9.2.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0258" published="2006-01-18" name="CVE-2006-0258" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Connection Manager component of Oracle Database server 8.1.7.4 and 9.0.1.5 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB03.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN">VU#545804</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA">18608</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="8.1.7.4"/>
        <vers num="9.0.1.5" edition=""/>
        <vers num="9.0.1.5" edition=":fips"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0259" published="2006-01-18" name="CVE-2006-0259" modified="2012-10-22" discovered="2006-01-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Oracle Database server 10.1.0.5 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) DB04 and (2) DB06 in the (a) Data Pump component; (3) DB10 in the (b) Net Listener component; and (4) DB16 in the (c) Oracle Text component.  NOTE: details are unavailable from Oracle, but they have not publicly disputed a claim by a reliable independent researcher that states that DB06 is SQL injection in the GENERATE_JOB_NAME, GET_WORKERSTATUSLIST1010, GET_PARAMVALUES1010, GET_DUMPFILESET1010, GET_JOBSTATUS1010, ATTACH, and ESTABLISH_REMOTE_CONTEXT functions in DBMS_DATAPUMP.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN" patch="1">VU#545804</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID" patch="1">16287</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" patch="1" adv="1">18493</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN" adv="1">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN" adv="1">ADV-2006-0243</ref>
      <ref url="http://www.osvdb.org/22544" source="OSVDB">22544</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" adv="1">18608</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0260" published="2006-01-18" name="CVE-2006-0260" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Oracle Database server 9.2.0.7 and 10.1.0.5 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) DB05 in the (a) Data Pump component; (2) DB15 in the (b) Oracle Text component; (3) DB22 in the (c) Streams Apply component; (4) DB23 and (5) DB24 in the (d) Streams Capture component; and (6) DB26 in the (e) Streams Subcomponent.  NOTE: details are unavailable from Oracle, but they have not publicly disputed a claim by a reliable independent researcher that states that DB05 involves SQL injection in the (f) LONG2VARCHAR, LONG2VCMAX, LONG2VCNT, and LONG2CLOB functions in the DBMS_METADATA_UTIL package; (g) MAKE_FILTER, FETCH_VIEWS_ERROR, FETCH_FILTERS, FETCH_VIEWS, SET_FILTER_COMMON, DO_FILTER_SCRIPT, SET_TABLE_FILTERS, and MAKE_FILTER_TEXT functions in the DBMS_METADATA_INT package; and (h) GET_PREPOST_TABLE_ACT function in the DBMS_METADATA package.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN" adv="1">VU#545804</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK" patch="1">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" patch="1" adv="1">18608</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN" adv="1">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN" adv="1">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://www.osvdb.org/22643" source="OSVDB">22643</ref>
      <ref url="http://www.osvdb.org/22637" source="OSVDB">22637</ref>
      <ref url="http://www.osvdb.org/22543" source="OSVDB">22543</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.5"/>
        <vers num="9.2.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0261" published="2006-01-18" name="CVE-2006-0261" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Oracle Database server 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.5 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) DB07 in the Dictionary component and (2) DB14 in the Oracle Label Security component.  NOTE: Oracle has not disputed reliable researcher claims that DB07 involves plaintext storage of the TDE wallet password in a trace file by event 10053.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN">VU#545804</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24168" source="XF">oracle-masterkey-plaintext(24168)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN" adv="1">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN" adv="1">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422255/30/7430/threaded" source="BUGTRAQ">20060117 Oracle Database 10g Rel. 2 - Event 10053 logs TDE wallet password in cleartext</ref>
      <ref url="http://www.red-database-security.com/advisory/oracle_tde_wallet_password.html" source="MISC">http://www.red-database-security.com/advisory/oracle_tde_wallet_password.html</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" adv="1">18608</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.5"/>
        <vers num="8.1.7.4"/>
        <vers num="9.0.1.5" edition=""/>
        <vers num="9.0.1.5" edition=":fips"/>
        <vers num="9.2.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0262" published="2006-01-18" name="CVE-2006-0262" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Net Foundation Layer component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.6, and 10.1.0.4 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB08.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN" adv="1">VU#545804</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" adv="1">18608</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="8.1.7.4"/>
      </prod>
      <prod vendor="oracle" name="oracle10g">
        <vers num="enterprise_10.1.0.4"/>
        <vers num="personal_10.1.0.4"/>
        <vers num="standard_10.1.0.4"/>
      </prod>
      <prod vendor="oracle" name="oracle8i">
        <vers num="enterprise_8.1.7.4"/>
        <vers num="standard_8.1.7.4"/>
      </prod>
      <prod vendor="oracle" name="oracle9i">
        <vers num="enterprise_9.0.1.5"/>
        <vers num="enterprise_9.0.1.5_fips"/>
        <vers num="standard_9.2.0.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0263" published="2006-01-18" name="CVE-2006-0263" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Oracle Database server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.7, 10.1.0.5, and 10.2.0.1 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) DB09 in the (a) Net Listener component; and (2) DB12 and (3) DB13 in the Network Communications (RPC) component.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-018A.html" source="CERT">TA06-018A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/870172" source="CERT-VN">VU#870172</ref>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN">VU#545804</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://www.osvdb.org/22551" source="OSVDB">22551</ref>
      <ref url="http://www.osvdb.org/22550" source="OSVDB">22550</ref>
      <ref url="http://www.osvdb.org/22547" source="OSVDB">22547</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" adv="1">18608</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.5"/>
        <vers num="10.2.0.1"/>
        <vers num="8.1.7.4"/>
        <vers num="9.0.1.5" edition=""/>
        <vers num="9.0.1.5" edition=":fips"/>
        <vers num="9.2.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2006-0264" reject="1" published="2006-01-18" name="CVE-2006-0264" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2006-0259.  Reason: This candidate is subsumed by CVE-2006-0259.  An error during initial CVE analysis used the wrong set of affected versions for "DB10". Notes: All CVE users should reference CVE-2006-0259 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0265" published="2006-01-18" name="CVE-2006-0265" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Oracle Database server 8.1.7.4, 9.0.1.5, 9.2.0.7, 10.1.0.5, and 10.2.0.1 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) DB17 in the Oracle Text component and (2) DB18 in the Program Interface Network component.  NOTE: details are unavailable from Oracle, but they have not publicly disputed a claim by a reliable independent researcher that states that DB17 involves SQL injection in the (a) VALIDATE_STATEMENT and BUILD_DML functions in CTXSYS.DRILOAD; (b) CLEAN_DML function in CTXSYS.DRIDML; (c) GET_ROWID function in CTXSYS.CTX_DOC; (d) BROWSE_WORDS function in CTXSYS.CTX_QUERY; and (e) ODCIINDEXTRUNCATE, ODCIINDEXDROP, and ODCIINDEXDELETE functions in CATINDEXMETHODS.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN" adv="1">VU#545804</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK" patch="1">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" patch="1" adv="1">18608</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN" adv="1">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN" adv="1">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html" source="MISC" adv="1">http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html</ref>
      <ref url="http://www.osvdb.org/22642" source="OSVDB">22642</ref>
      <ref url="http://www.osvdb.org/22641" source="OSVDB">22641</ref>
      <ref url="http://www.osvdb.org/22640" source="OSVDB">22640</ref>
      <ref url="http://www.osvdb.org/22639" source="OSVDB">22639</ref>
      <ref url="http://www.osvdb.org/22555" source="OSVDB">22555</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.5"/>
        <vers num="10.2.0.1"/>
        <vers num="8.1.7.4"/>
        <vers num="9.0.1.5"/>
        <vers num="9.2.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0266" published="2006-01-18" name="CVE-2006-0266" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Query Optimizer component of Oracle Database server 9.0.1.5, 9.2.0.7, and 10.1.0.5 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB19.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN">VU#545804</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" adv="1">18608</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.5"/>
        <vers num="9.0.1.5"/>
        <vers num="9.2.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0267" published="2006-01-18" name="CVE-2006-0267" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Query Optimizer component of Oracle Database server 9.2.0.6 and 10.1.0.4 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB20.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN">VU#545804</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" adv="1">18608</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.4"/>
        <vers num="9.2.0.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0268" published="2006-01-18" name="CVE-2006-0268" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Security component of Oracle Database server 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.6, and 10.1.0.4 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB21.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN">VU#545804</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" adv="1">18608</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.4"/>
        <vers num="9.0.1.5" edition=""/>
        <vers num="9.0.1.5" edition=":fips"/>
        <vers num="9.2.0.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0269" published="2006-01-18" name="CVE-2006-0269" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)" CVSS_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_base_score="5.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Streams Capture component of Oracle Database server 10.1.0.5 and 10.2.0.1 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB25.  NOTE: details are unavailable from Oracle, but they have not publicly disputed a claim by a reliable independent researcher that states that the problem is SQL injection in the SET_DIRECTORY_ROOT function in the DBMS_CDC_PUBLISH package.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN" adv="1">VU#545804</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN" adv="1">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN" adv="1">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html" source="MISC">http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html</ref>
      <ref url="http://www.osvdb.org/22563" source="OSVDB">22563</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" adv="1">18608</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="oracle10g">
        <vers num="standard_10.1.0.5"/>
        <vers num="standard_10.2.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0270" published="2006-01-18" name="CVE-2006-0270" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Transparent Data Encryption (TDE) Wallet component of Oracle Database server 10.2.0.1 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB27.  NOTE: Oracle has not disputed a reliable researcher report that TDA stores the master key without encryption, which allows local users to obtain the key via the SGA.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN">VU#545804</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24186" source="XF">oracle-sga-masterkey-plaintext(24186)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN" adv="1">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN" adv="1">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422262/30/7400/threaded" source="BUGTRAQ">20060117 Oracle Database 10g Rel. 2- Transparent Data Encryption plaintext masterkey in SGA</ref>
      <ref url="http://www.red-database-security.com/advisory/oracle_tde_unencrypted_sga.html" source="MISC">http://www.red-database-security.com/advisory/oracle_tde_unencrypted_sga.html</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" adv="1">18608</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.2.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0271" published="2006-01-18" name="CVE-2006-0271" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Upgrade &amp; Downgrade component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.4 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB28.  NOTE: details are unavailable from Oracle, but they have not publicly disputed a claim by a reliable independent researcher that states that the problem is SQL injection in the DBMS_REGISTRY package in certain parameters to the (1) IS_COMPONENT, (2) GET_COMP_OPTION, (3) DISABLE_DDL_TRIGGERS, (4) SCRIPT_EXISTS, (5) COMP_PATH, (6) GATHER_STATS, (7) NOTHING_SCRIPT, and (8) VALIDATE_COMPONENTS functions.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN">VU#545804</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN" adv="1">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN" adv="1">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html" source="MISC">http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html</ref>
      <ref url="http://www.osvdb.org/22566" source="OSVDB">22566</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" adv="1">18608</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="8.1.7.4"/>
      </prod>
      <prod vendor="oracle" name="oracle10g">
        <vers num="enterprise_10.1.0.4"/>
        <vers num="personal_10.1.0.4"/>
        <vers num="standard_10.1.0.4"/>
      </prod>
      <prod vendor="oracle" name="oracle8i">
        <vers num="enterprise_8.1.7.4"/>
        <vers num="standard_8.1.7.4"/>
      </prod>
      <prod vendor="oracle" name="oracle9i">
        <vers num="enterprise_9.0.1.5"/>
        <vers num="standard_9.2.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0272" published="2006-01-18" name="CVE-2006-0272" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the XML Database component of Oracle Database server 9.2.0.7 and 10.1.0.4 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB29.  NOTE: based on mutual credits by the relevant sources, it is highly likely that this issue is a buffer overflow in the (a) DBMS_XMLSCHEMA and (b) DBMS_XMLSCHEMA_INT packages, as exploitable via long arguments to (1) XDB.DBMS_XMLSCHEMA.GENERATESCHEMA or (2) XDB.DBMS_XMLSCHEMA.GENERATESCHEMAS.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-018A.html" source="CERT">TA06-018A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/891644" source="CERT-VN">VU#891644</ref>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN" adv="1">VU#545804</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24376" source="XF">oracle-xdbdbmx-xmlschema-bo(24376)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN" adv="1">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN" adv="1">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html" source="MISC">http://www.red-database-security.com/advisory/oracle_cpu_jan_2006.html</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html</ref>
      <ref url="http://www.integrigy.com/info/IntegrigySecurityAnalysis-CPU0106.pdf" source="MISC">http://www.integrigy.com/info/IntegrigySecurityAnalysis-CPU0106.pdf</ref>
      <ref url="http://www.argeniss.com/research/ARGENISS-ADV-010601.txt" source="MISC">http://www.argeniss.com/research/ARGENISS-ADV-010601.txt</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" adv="1">18608</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0893.html" source="FULLDISC">20060126 [Argeniss] Oracle Database Buffer overflows vulnerabilities in public procedures of XDB.DBMS_XMLSCHEMA{_INT}</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="oracle10g">
        <vers num="enterprise_10.1.0.4"/>
        <vers num="personal_10.1.0.4"/>
        <vers num="standard_10.1.0.4"/>
      </prod>
      <prod vendor="oracle" name="oracle9i">
        <vers num="standard_9.2.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0273" published="2006-01-18" name="CVE-2006-0273" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Portal component of Oracle Application Server 9.0.4.2 and 10.1.2.0 has unspecified impact and attack vectors, as identified by Oracle Vuln# AS01.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN" adv="1">VU#545804</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" adv="1">18608</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="10.1.2.0"/>
        <vers num="9.0.4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0274" published="2006-01-18" name="CVE-2006-0274" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle Reports Developer component of Oracle Application Server 9.0.4.2 and 10.1.2.0.2 has unspecified impact and attack vectors, as identified by Oracle Vuln# REP03.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN">VU#545804</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" adv="1">18608</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="10.1.2.0.2"/>
        <vers num="9.0.4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0275" published="2006-01-18" name="CVE-2006-0275" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle Reports Developer component of Oracle Application Server 9.0.4.2 has unspecified impact and attack vectors, as identified by Oracle Vuln# REP04.  NOTE: Oracle has not disputed reliable researcher claims that this issue is related to directory traversal that allows reading of portions of arbitrary XML files via the customize parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN" adv="1">VU#545804</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN" adv="1">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN" adv="1">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422261/30/7430/threaded" source="BUGTRAQ">20060117 Oracle Reports - Read parts of files via customize(fixed after 875 days)</ref>
      <ref url="http://www.red-database-security.com/advisory/oracle_reports_read_any_xml_file.html" source="MISC">http://www.red-database-security.com/advisory/oracle_reports_read_any_xml_file.html</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" adv="1">18608</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="9.0.4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0276" published="2006-01-18" name="CVE-2006-0276" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Oracle Collaboration Suite Release 2, version 9.0.4.2 (Oracle9i) have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) OCS01, 2) OCS02, 3) OCS03, 4) OCS04, 5) OCS05, 6) OCS06, 7) OCS07, (8) OCS08, and (9) OCS09 in the (a) Email Server component; 10) OCS10 (and (11) OCS11 in the (b) Oracle Collaboration Suite Wireless &amp; Voice (component; 12) OCS12 and (13) OCS13 in the (c) Oracle Content (Management SDK component; 14) OCS14 and (15) OCS15 in the (d) Oracle (Content Services component.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN" adv="1">VU#545804</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK" patch="1">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" patch="1" adv="1">18608</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN" adv="1">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN" adv="1">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="collaboration_suite">
        <vers num="9.0.4.2" edition="r2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0277" published="2006-01-18" name="CVE-2006-0277" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Oracle E-Business Suite and Applications 11.5.10 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) APPS01 in the (a) Application Install component; (2) APPS07 in the (b) Oracle Applications Framework component; (3) APPS08, (4) APPS09, (5) APPS10, and (6) APPS11 in the (c) Oracle Applications Technology Stack component; (7) APPS12 in the (d) Oracle Human Resources component; (8) APPS15 and (9) APPS16 in the (e) Oracle Marketing component; (10) APPS17 in the (f) Marketing Encyclopedia System component; (11) APPS18 in the (g) Oracle Trade Management component; and (12) APPS19 in the (h) Oracle Web Applications Desktop Integration component.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN">VU#545804</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" adv="1">18608</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0278" published="2006-01-18" name="CVE-2006-0278" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Oracle E-Business Suite and Applications 11.5.9 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) APPS02 in the (a) CRM Technical Foundation component; (2) APPS03 in the (b) iProcurement component; and (3) APPS04, (4) APPS05, and (5) APPS06 in the Oracle Application Object Library component.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN" adv="1">VU#545804</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" adv="1">18608</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0279" published="2006-01-18" name="CVE-2006-0279" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Oracle E-Business Suite and Applications 4.3 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) APPS13 and (2) APPS14 in the Oracle iLearning component.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN">VU#545804</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" adv="1">18608</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="4.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0280" published="2006-01-18" name="CVE-2006-0280" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle PeopleSoft Enterprise Portal 8.4 Bundle 15, 8.8 Bundle 10, and 8.9 Bundle 2 has unspecified impact and attack vectors, as identified by Oracle Vuln# PSE01.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN">VU#545804</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" adv="1">18608</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="peoplesoft_enterprise_portal">
        <vers num="8.4" edition="bundle15"/>
        <vers num="8.8" edition="bundle10"/>
        <vers num="8.9" edition="bundle2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0281" published="2006-01-18" name="CVE-2006-0281" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle JD Edwards HTML Server 8.95.F1 SP23_L1 has unspecified impact and attack vectors, as identified by Oracle Vuln# JDE01.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN">VU#545804</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" adv="1">18608</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="enterpriseone">
        <vers num="8.95.f1"/>
        <vers num="sp23_l1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0282" published="2006-01-18" name="CVE-2006-0282" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle Database Server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.7, and 10.1.0.5, Application Server 1.0.2.2, 9.0.4.2, and 10.1.2.0.2, and Collaboration Suite Release 2, version 9.0.4.2 (Oracle9i) has unspecified impact and attack vectors, as identified by Oracle Vuln# DBC01 in the Protocol Support component.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN">VU#545804</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" adv="1">18608</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="1.0.2.2" edition="r1"/>
        <vers num="10.1.2.0.2" edition="r2"/>
        <vers num="9.0.4.2"/>
      </prod>
      <prod vendor="oracle" name="collaboration_suite">
        <vers num="9.0.4.2" edition="r2"/>
      </prod>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.5"/>
        <vers num="8.1.7.4"/>
        <vers num="9.0.1.5" edition=""/>
        <vers num="9.0.1.5" edition=":fips"/>
        <vers num="9.2.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0283" published="2006-01-18" name="CVE-2006-0283" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle Database Server 10.1.0.4.2, Application Server 10.1.2.0.2, and Collaboration Suite Release 2, version 9.0.4.2 (Oracle9i) has unspecified impact and attack vectors, as identified by Oracle Vuln# DBC02 in the Reorganize Objects &amp; Convert Tablespace component.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN" adv="1">VU#545804</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK" patch="1">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" patch="1" adv="1">18608</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN" adv="1">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN" adv="1">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="10.1.2.0.2"/>
      </prod>
      <prod vendor="oracle" name="collaboration_suite">
        <vers num="9.0.4.2" edition="r2"/>
      </prod>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0284" published="2006-01-18" name="CVE-2006-0284" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Oracle Application Server 9.0.4.2 and 10.1.2.0.2, and E-Business Suite and Applications 11.5.10, have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) FORM01 and (2) FORM02 in the Oracle Forms component.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN">VU#545804</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" adv="1">18608</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="10.1.2.0.2" edition="r2"/>
        <vers num="9.0.4.2"/>
      </prod>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0285" published="2006-01-18" name="CVE-2006-0285" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Net component of Oracle Database Server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.7, and 10.1.0.4, and Application Server 1.0.2.2, 9.0.4.2, and 10.1.2.0.2, has unspecified impact and attack vectors, as identified by Oracle Vuln# JN01.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN">VU#545804</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" adv="1">18608</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="1.0.2.2"/>
        <vers num="10.1.2.0.2"/>
        <vers num="9.0.4.2"/>
      </prod>
      <prod vendor="oracle" name="database_server">
        <vers num="8.1.7.4"/>
        <vers num="9.0.1.5" edition=""/>
        <vers num="9.0.1.5" edition=":fips"/>
        <vers num="9.2.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0286" published="2006-01-18" name="CVE-2006-0286" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle HTTP Server component of Oracle Database Server 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.7, and 10.1.0.5, and Application Server 1.0.2.2, 9.0.4.2, and 10.1.2.0.2, has unspecified impact and attack vectors, as identified by Oracle Vuln# OHS01.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN">VU#545804</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" adv="1">18608</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="1.0.2.2"/>
        <vers num="10.1.2.0.2"/>
        <vers num="9.0.4.2"/>
      </prod>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.5"/>
        <vers num="9.0.1.5" edition=""/>
        <vers num="9.0.1.5" edition=":fips"/>
        <vers num="9.2.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0287" published="2006-01-18" name="CVE-2006-0287" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle HTTP Server component of Oracle Database Server 10.1.0.5 and Application Server 10.1.2.0.2 has unspecified impact and attack vectors, as identified by Oracle Vuln# OHS02.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN">VU#545804</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" adv="1">18608</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="10.1.2.0.2"/>
      </prod>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0288" published="2006-01-18" name="CVE-2006-0288" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in the Oracle Reports Developer component of Oracle Application Server 9.0.4.1 and E-Business Suite and Applications 11.5.10 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) REP01 and (2) REP02.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN" adv="1">VU#545804</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK" patch="1">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" patch="1" adv="1">18608</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN" adv="1">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN" adv="1">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="9.0.4.1"/>
      </prod>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0289" published="2006-01-18" name="CVE-2006-0289" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Oracle Application Server 6.0.8.26(PS17) and E-Business Suite and Applications 11.5.10 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) REP05 and (2) REP06 in the Oracle Reports Developer component. NOTE: Oracle has not disputed reliable researcher claims that REP05 is the same as CVE-2005-2378 and REP06 is the same as CVE-2005-2371, both of which involve directory traversal.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN">VU#545804</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN" adv="1">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN" adv="1">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422257/30/7430/threaded" source="BUGTRAQ">20060117 Oracle Reports - Overwrite any application server file via desname (fixed after 889 days)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422256/30/7430/threaded" source="BUGTRAQ">20060117 Oracle Reports - Read parts of files via desname (fixed after 874 days)</ref>
      <ref url="http://www.red-database-security.com/advisory/oracle_reports_read_any_file.html" source="MISC">http://www.red-database-security.com/advisory/oracle_reports_read_any_file.html</ref>
      <ref url="http://www.red-database-security.com/advisory/oracle_reports_overwrite_any_file.html" source="MISC">http://www.red-database-security.com/advisory/oracle_reports_overwrite_any_file.html</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" adv="1">18608</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="6.0.8.26_ps17"/>
      </prod>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0290" published="2006-01-18" name="CVE-2006-0290" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle Database Server 9.2.0.7, Application Server 9.0.4.2 and 10.1.2.1, Collaboration Suite Release 2, version 9.0.4.2 (Oracle9i), and E-Business Suite and Applications 11.5.10 has unspecified impact and attack vectors, as identified by Oracle Vuln# WF01 in the Oracle Workflow Cartridge component.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN">VU#545804</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" adv="1">18608</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="10.1.2.1"/>
        <vers num="9.0.4.2"/>
      </prod>
      <prod vendor="oracle" name="collaboration_suite">
        <vers num="9.0.4.2" edition="r2"/>
      </prod>
      <prod vendor="oracle" name="database_server">
        <vers num="9.2.0.7"/>
      </prod>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0291" published="2006-01-18" name="CVE-2006-0291" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Oracle Database Server 10.2.0.1, Application Server 9.0.4.2 and 10.1.2.1, Collaboration Suite Release 2, version 9.0.4.2 (Oracle9i), and E-Business Suite and Applications 11.5.10 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) WF02 and (2) WF03 in the Oracle Workflow Cartridge component.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/545804" source="CERT-VN">VU#545804</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24321" source="XF">oracle-january2006-update(24321)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0323" source="VUPEN">ADV-2006-0323</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0243" source="VUPEN">ADV-2006-0243</ref>
      <ref url="http://www.securityfocus.com/bid/16287" source="BID">16287</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html</ref>
      <ref url="http://securitytracker.com/id?1015499" source="SECTRACK">1015499</ref>
      <ref url="http://secunia.com/advisories/18608" source="SECUNIA" adv="1">18608</ref>
      <ref url="http://secunia.com/advisories/18493" source="SECUNIA" adv="1">18493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="10.1.2.1.0"/>
        <vers num="9.0.4.2"/>
      </prod>
      <prod vendor="oracle" name="collaboration_suite">
        <vers num="9.0.4.2" edition="r2"/>
      </prod>
      <prod vendor="oracle" name="database_server">
        <vers num="10.2.0.1"/>
      </prod>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11.5.10"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0292" published="2006-02-02" name="CVE-2006-0292" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Javascript interpreter (jsinterp.c) in Mozilla and Firefox before 1.5.1 does not properly dereference objects, which allows remote attackers to cause a denial of service (crash) or execute arbitrary code via unknown attack vectors related to garbage collection.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=316885" source="CONFIRM" patch="1">https://bugzilla.mozilla.org/show_bug.cgi?id=316885</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3749" source="VUPEN">ADV-2006-3749</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3391" source="VUPEN">ADV-2006-3391</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0413" source="VUPEN">ADV-2006-0413</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded" source="HP">HPSBUX02156</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded" source="HP">SSRT061158</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0200.html" source="REDHAT" adv="1">RHSA-2006:0200</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0199.html" source="REDHAT" adv="1">RHSA-2006:0199</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-228526-1" source="SUNALERT">228526</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10016" source="OVAL">oval:org.mitre.oval:def:10016</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24430" source="XF">mozilla-javascript-memory-corruption(24430)</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-276-1" source="UBUNTU">USN-276-1</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-275-1" source="UBUNTU">USN-275-1</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-271-1" source="UBUNTU">USN-271-1</ref>
      <ref url="http://www.securityfocus.com/bid/16476" source="BID">16476</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded" source="HP">HPSBUX02156</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded" source="HP">HPSBUX02122</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425978/100/0/threaded" source="FEDORA">FLSA-2006:180036-2</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425975/100/0/threaded" source="FEDORA">FLSA:180036-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0330.html" source="REDHAT">RHSA-2006:0330</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-February/msg00006.html" source="FEDORA">FEDORA-2006-076</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-February/msg00005.html" source="FEDORA">FEDORA-2006-075</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://www.mozilla.org/security/announce/2006/mfsa2006-01.html" source="CONFIRM">http://www.mozilla.org/security/announce/2006/mfsa2006-01.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:078" source="MANDRIVA">MDKSA-2006:078</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:037" source="MANDRIVA">MDKSA-2006:037</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:036" source="MANDRIVA">MDKSA-2006:036</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200605-09.xml" source="GENTOO">GLSA-200605-09</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml" source="GENTOO">GLSA-200604-18</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-12.xml" source="GENTOO">GLSA-200604-12</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1051" source="DEBIAN">DSA-1051</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1046" source="DEBIAN">DSA-1046</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1044" source="DEBIAN">DSA-1044</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1" source="SUNALERT">102550</ref>
      <ref url="http://securitytracker.com/id?1015570" source="SECTRACK">1015570</ref>
      <ref url="http://secunia.com/advisories/22065" source="SECUNIA">22065</ref>
      <ref url="http://secunia.com/advisories/21622" source="SECUNIA">21622</ref>
      <ref url="http://secunia.com/advisories/21033" source="SECUNIA">21033</ref>
      <ref url="http://secunia.com/advisories/20051" source="SECUNIA">20051</ref>
      <ref url="http://secunia.com/advisories/19950" source="SECUNIA">19950</ref>
      <ref url="http://secunia.com/advisories/19941" source="SECUNIA">19941</ref>
      <ref url="http://secunia.com/advisories/19902" source="SECUNIA">19902</ref>
      <ref url="http://secunia.com/advisories/19863" source="SECUNIA">19863</ref>
      <ref url="http://secunia.com/advisories/19862" source="SECUNIA">19862</ref>
      <ref url="http://secunia.com/advisories/19852" source="SECUNIA">19852</ref>
      <ref url="http://secunia.com/advisories/19823" source="SECUNIA">19823</ref>
      <ref url="http://secunia.com/advisories/19821" source="SECUNIA">19821</ref>
      <ref url="http://secunia.com/advisories/19780" source="SECUNIA">19780</ref>
      <ref url="http://secunia.com/advisories/19759" source="SECUNIA">19759</ref>
      <ref url="http://secunia.com/advisories/19746" source="SECUNIA">19746</ref>
      <ref url="http://secunia.com/advisories/19230" source="SECUNIA">19230</ref>
      <ref url="http://secunia.com/advisories/18709" source="SECUNIA">18709</ref>
      <ref url="http://secunia.com/advisories/18708" source="SECUNIA">18708</ref>
      <ref url="http://secunia.com/advisories/18706" source="SECUNIA">18706</ref>
      <ref url="http://secunia.com/advisories/18705" source="SECUNIA">18705</ref>
      <ref url="http://secunia.com/advisories/18704" source="SECUNIA">18704</ref>
      <ref url="http://secunia.com/advisories/18703" source="SECUNIA">18703</ref>
      <ref url="http://secunia.com/advisories/18700" source="SECUNIA">18700</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060201-01-U" source="SGI">20060201-01-U</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt" source="SCO">SCOSA-2006.26</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:670" source="OVAL" sig="1">oval:org.mitre.oval:def:670</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.10"/>
        <vers num="0.10.1"/>
        <vers num="0.8"/>
        <vers num="0.9" edition="rc"/>
        <vers num="0.9.1"/>
        <vers num="0.9.2"/>
        <vers num="0.9.3"/>
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6" edition=""/>
        <vers num="1.0.6" edition=":linux"/>
        <vers num="1.0.7"/>
        <vers num="1.5" edition="beta1"/>
      </prod>
      <prod vendor="mozilla" name="mozilla">
        <vers num="1.4"/>
        <vers num="1.4.1"/>
        <vers num="1.5" edition="alpha"/>
        <vers num="1.5" edition="rc1"/>
        <vers num="1.5" edition="rc2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0293" published="2006-02-02" name="CVE-2006-0293" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The function allocation code (js_NewFunction in jsfun.c) in Firefox 1.5 allows attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via user-defined methods that trigger garbage collection in a way that operates on freed objects.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=322045" source="CONFIRM" patch="1">https://bugzilla.mozilla.org/show_bug.cgi?id=322045</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3749" source="VUPEN">ADV-2006-3749</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3391" source="VUPEN">ADV-2006-3391</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0413" source="VUPEN">ADV-2006-0413</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded" source="HP">SSRT061236</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded" source="HP">SSRT061158</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-228526-1" source="SUNALERT">228526</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/42654" source="XF">firefox-function-allocation-code-execution(42654)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24430" source="XF">mozilla-javascript-memory-corruption(24430)</ref>
      <ref url="http://www.securityfocus.com/bid/16476" source="BID">16476</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded" source="HP">SSRT061236</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded" source="HP">SSRT061158</ref>
      <ref url="http://www.mozilla.org/security/announce/2006/mfsa2006-01.html" source="CONFIRM">http://www.mozilla.org/security/announce/2006/mfsa2006-01.html</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml" source="GENTOO">GLSA-200604-18</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1051" source="DEBIAN">DSA-1051</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1046" source="DEBIAN">DSA-1046</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1044" source="DEBIAN">DSA-1044</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1" source="SUNALERT">102550</ref>
      <ref url="http://securitytracker.com/id?1015570" source="SECTRACK">1015570</ref>
      <ref url="http://secunia.com/advisories/22065" source="SECUNIA">22065</ref>
      <ref url="http://secunia.com/advisories/21622" source="SECUNIA">21622</ref>
      <ref url="http://secunia.com/advisories/19941" source="SECUNIA">19941</ref>
      <ref url="http://secunia.com/advisories/19902" source="SECUNIA">19902</ref>
      <ref url="http://secunia.com/advisories/19863" source="SECUNIA">19863</ref>
      <ref url="http://secunia.com/advisories/19862" source="SECUNIA">19862</ref>
      <ref url="http://secunia.com/advisories/18704" source="SECUNIA">18704</ref>
      <ref url="http://secunia.com/advisories/18700" source="SECUNIA">18700</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1494" source="OVAL" sig="1">oval:org.mitre.oval:def:1494</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0294" published="2006-02-02" name="CVE-2006-0294" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in mail, and SeaMonkey before 1.0 allow remote attackers to execute arbitrary code by changing an element's style from position:relative to position:static, which causes Gecko to operate on freed memory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=317934" source="CONFIRM" patch="1">https://bugzilla.mozilla.org/show_bug.cgi?id=317934</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3749" source="VUPEN">ADV-2006-3749</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0413" source="VUPEN">ADV-2006-0413</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded" source="HP">SSRT061236</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24431" source="XF">mozilla-element-change-memory-corruption(24431)</ref>
      <ref url="http://www.securityfocus.com/bid/16476" source="BID">16476</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded" source="HP">HPSBUX02156</ref>
      <ref url="http://www.mozilla.org/security/announce/2006/mfsa2006-02.html" source="CONFIRM">http://www.mozilla.org/security/announce/2006/mfsa2006-02.html</ref>
      <ref url="http://securitytracker.com/id?1015570" source="SECTRACK">1015570</ref>
      <ref url="http://secunia.com/advisories/22065" source="SECUNIA">22065</ref>
      <ref url="http://secunia.com/advisories/18704" source="SECUNIA">18704</ref>
      <ref url="http://secunia.com/advisories/18700" source="SECUNIA">18700</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1514" source="OVAL" sig="1">oval:org.mitre.oval:def:1514</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.10"/>
        <vers num="0.10.1"/>
        <vers num="0.8"/>
        <vers num="0.9" edition="rc"/>
        <vers num="0.9.1"/>
        <vers num="0.9.2"/>
        <vers num="0.9.3"/>
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6" edition=""/>
        <vers num="1.0.6" edition=":linux"/>
        <vers num="1.0.7"/>
        <vers num="1.5" edition="beta1"/>
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition=""/>
        <vers num="1.0" edition=":alpha"/>
        <vers num="1.0" edition="beta"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="1.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0295" published="2006-02-02" name="CVE-2006-0295" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attackers to execute arbitrary code via the QueryInterface method of the built-in Location and Navigator objects, which leads to memory corruption.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <config/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-038A.html" source="CERT">TA06-038A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/759273" source="CERT-VN">VU#759273</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=319296" source="CONFIRM" patch="1">https://bugzilla.mozilla.org/show_bug.cgi?id=319296</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3749" source="VUPEN">ADV-2006-3749</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0413" source="VUPEN">ADV-2006-0413</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded" source="HP">SSRT061236</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24433" source="XF">mozilla-queryinterface-memory-corruption(24433)</ref>
      <ref url="http://www.securityfocus.com/bid/16476" source="BID">16476</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded" source="HP">HPSBUX02156</ref>
      <ref url="http://www.mozilla.org/security/announce/2006/mfsa2006-04.html" source="CONFIRM">http://www.mozilla.org/security/announce/2006/mfsa2006-04.html</ref>
      <ref url="http://securitytracker.com/id?1015570" source="SECTRACK">1015570</ref>
      <ref url="http://secunia.com/advisories/22065" source="SECUNIA">22065</ref>
      <ref url="http://secunia.com/advisories/18704" source="SECUNIA">18704</ref>
      <ref url="http://secunia.com/advisories/18700" source="SECUNIA">18700</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1562" source="OVAL" sig="1">oval:org.mitre.oval:def:1562</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.5"/>
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition=""/>
        <vers num="1.0" edition=":alpha"/>
        <vers num="1.0" edition="beta"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="1.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0296" published="2006-02-02" name="CVE-2006-0296" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The XULDocument.persist function in Mozilla, Firefox before 1.5.0.1, and SeaMonkey before 1.0 does not validate the attribute name, which allows remote attackers to execute arbitrary Javascript by injecting RDF data into the user's localstore.rdf file.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-038A.html" source="CERT">TA06-038A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/592425" source="CERT-VN">VU#592425</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=319847" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=319847</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3749" source="VUPEN">ADV-2006-3749</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3391" source="VUPEN">ADV-2006-3391</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0413" source="VUPEN">ADV-2006-0413</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded" source="HP">SSRT061236</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded" source="HP">SSRT061158</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0200.html" source="REDHAT" adv="1">RHSA-2006:0200</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0199.html" source="REDHAT" adv="1">RHSA-2006:0199</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-228526-1" source="SUNALERT">228526</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11803" source="OVAL">oval:org.mitre.oval:def:11803</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24434" source="XF">mozilla-xuldocument-command-execution(24434)</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-276-1" source="UBUNTU">USN-276-1</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-275-1" source="UBUNTU">USN-275-1</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-271-1" source="UBUNTU">USN-271-1</ref>
      <ref url="http://www.securityfocus.com/bid/16476" source="BID">16476</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded" source="HP">HPSBUX02156</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/438730/100/0/threaded" source="HP">SSRT061158</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425978/100/0/threaded" source="FEDORA">FLSA-2006:180036-2</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425975/100/0/threaded" source="FEDORA">FLSA:180036-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0330.html" source="REDHAT">RHSA-2006:0330</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-February/msg00006.html" source="FEDORA">FEDORA-2006-076</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-February/msg00005.html" source="FEDORA">FEDORA-2006-075</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_04_25.html" source="SUSE">SUSE-SA:2006:004</ref>
      <ref url="http://www.mozilla.org/security/announce/2006/mfsa2006-05.html" source="CONFIRM">http://www.mozilla.org/security/announce/2006/mfsa2006-05.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:078" source="MANDRIVA">MDKSA-2006:078</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:037" source="MANDRIVA">MDKSA-2006:037</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:036" source="MANDRIVA">MDKSA-2006:036</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200605-09.xml" source="GENTOO">GLSA-200605-09</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-18.xml" source="GENTOO">GLSA-200604-18</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-12.xml" source="GENTOO">GLSA-200604-12</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1051" source="DEBIAN">DSA-1051</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1046" source="DEBIAN">DSA-1046</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1044" source="DEBIAN">DSA-1044</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-205.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102550-1" source="SUNALERT">102550</ref>
      <ref url="http://securitytracker.com/id?1015570" source="SECTRACK">1015570</ref>
      <ref url="http://secunia.com/advisories/22065" source="SECUNIA">22065</ref>
      <ref url="http://secunia.com/advisories/21622" source="SECUNIA">21622</ref>
      <ref url="http://secunia.com/advisories/21033" source="SECUNIA">21033</ref>
      <ref url="http://secunia.com/advisories/20051" source="SECUNIA">20051</ref>
      <ref url="http://secunia.com/advisories/19950" source="SECUNIA">19950</ref>
      <ref url="http://secunia.com/advisories/19941" source="SECUNIA">19941</ref>
      <ref url="http://secunia.com/advisories/19902" source="SECUNIA">19902</ref>
      <ref url="http://secunia.com/advisories/19863" source="SECUNIA">19863</ref>
      <ref url="http://secunia.com/advisories/19862" source="SECUNIA">19862</ref>
      <ref url="http://secunia.com/advisories/19852" source="SECUNIA">19852</ref>
      <ref url="http://secunia.com/advisories/19823" source="SECUNIA">19823</ref>
      <ref url="http://secunia.com/advisories/19821" source="SECUNIA">19821</ref>
      <ref url="http://secunia.com/advisories/19780" source="SECUNIA">19780</ref>
      <ref url="http://secunia.com/advisories/19759" source="SECUNIA">19759</ref>
      <ref url="http://secunia.com/advisories/19746" source="SECUNIA">19746</ref>
      <ref url="http://secunia.com/advisories/19230" source="SECUNIA">19230</ref>
      <ref url="http://secunia.com/advisories/18709" source="SECUNIA">18709</ref>
      <ref url="http://secunia.com/advisories/18708" source="SECUNIA">18708</ref>
      <ref url="http://secunia.com/advisories/18706" source="SECUNIA">18706</ref>
      <ref url="http://secunia.com/advisories/18705" source="SECUNIA">18705</ref>
      <ref url="http://secunia.com/advisories/18704" source="SECUNIA">18704</ref>
      <ref url="http://secunia.com/advisories/18703" source="SECUNIA">18703</ref>
      <ref url="http://secunia.com/advisories/18700" source="SECUNIA">18700</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060201-01-U" source="SGI">20060201-01-U</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.26/SCOSA-2006.26.txt" source="SCO">SCOSA-2006.26</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1493" source="OVAL" sig="1">oval:org.mitre.oval:def:1493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.10"/>
        <vers num="0.10.1"/>
        <vers num="0.8"/>
        <vers num="0.9" edition="rc"/>
        <vers num="0.9.1"/>
        <vers num="0.9.2"/>
        <vers num="0.9.3"/>
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6" edition=""/>
        <vers num="1.0.6" edition=":linux"/>
        <vers num="1.0.7"/>
        <vers num="1.5" edition="beta1"/>
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition=""/>
        <vers num="1.0" edition=":alpha"/>
        <vers num="1.0" edition="beta"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0297" published="2006-02-02" name="CVE-2006-0297" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Multiple integer overflows in Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attackers to execute arbitrary code via the (1) EscapeAttributeValue in jsxml.c for E4X, (2) nsSVGCairoSurface::Init in SVG, and (3) nsCanvasRenderingContext2D.cpp in Canvas.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=322215" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=322215</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=319872" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=319872</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24435" source="XF">mozilla-component-integer-overflow(24435)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3749" source="VUPEN">ADV-2006-3749</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0413" source="VUPEN">ADV-2006-0413</ref>
      <ref url="http://www.securityfocus.com/bid/16476" source="BID">16476</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded" source="HP">SSRT061236</ref>
      <ref url="http://securitytracker.com/id?1015570" source="SECTRACK">1015570</ref>
      <ref url="http://secunia.com/advisories/18704" source="SECUNIA">18704</ref>
      <ref url="http://secunia.com/advisories/18700" source="SECUNIA">18700</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded" source="HP">HPSBUX02156</ref>
      <ref url="http://www.mozilla.org/security/announce/2006/mfsa2006-06.html" source="CONFIRM">http://www.mozilla.org/security/announce/2006/mfsa2006-06.html</ref>
      <ref url="http://secunia.com/advisories/22065" source="SECUNIA">22065</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1339" source="OVAL" sig="1">oval:org.mitre.oval:def:1339</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.5" edition="beta1"/>
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition=""/>
        <vers num="1.0" edition=":alpha"/>
        <vers num="1.0" edition="beta"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="1.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0298" published="2006-02-02" name="CVE-2006-0298" modified="2011-05-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:P)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">The XML parser in Mozilla Firefox before 1.5.0.1 and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly read sensitive data via unknown attack vectors that trigger an out-of-bounds read.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24436" source="XF" patch="1">mozilla-xml-parser-dos(24436)</ref>
      <ref url="http://www.securityfocus.com/bid/16476" source="BID" patch="1">16476</ref>
      <ref url="http://securitytracker.com/id?1015570" source="SECTRACK" patch="1">1015570</ref>
      <ref url="http://secunia.com/advisories/18704" source="SECUNIA" patch="1" adv="1">18704</ref>
      <ref url="http://secunia.com/advisories/18700" source="SECUNIA" patch="1" adv="1">18700</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3749" source="VUPEN" adv="1">ADV-2006-3749</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0413" source="VUPEN" adv="1">ADV-2006-0413</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded" source="HP">SSRT061236</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded" source="HP">SSRT061236</ref>
      <ref url="http://www.mozilla.org/security/announce/2006/mfsa2006-07.html" source="CONFIRM">http://www.mozilla.org/security/announce/2006/mfsa2006-07.html</ref>
      <ref url="http://secunia.com/advisories/22065" source="SECUNIA" adv="1">22065</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:677" source="OVAL" sig="1">oval:org.mitre.oval:def:677</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.5" edition="beta1"/>
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition=""/>
        <vers num="1.0" edition=":alpha"/>
        <vers num="1.0" edition="beta"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0299" published="2006-02-02" name="CVE-2006-0299" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">The E4X implementation in Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in mail, and SeaMonkey before 1.0 exposes the internal "AnyName" object to external interfaces, which allows multiple cooperating domains to exchange information in violation of the same origin restrictions.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=322312" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=322312</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3749" source="VUPEN">ADV-2006-3749</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0413" source="VUPEN">ADV-2006-0413</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded" source="HP">SSRT061236</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24437" source="XF">mozilla-e4x-security-bypass(24437)</ref>
      <ref url="http://www.securityfocus.com/bid/16476" source="BID">16476</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446657/100/200/threaded" source="HP">SSRT061236</ref>
      <ref url="http://www.mozilla.org/security/announce/2006/mfsa2006-08.html" source="CONFIRM">http://www.mozilla.org/security/announce/2006/mfsa2006-08.html</ref>
      <ref url="http://securitytracker.com/id?1015570" source="SECTRACK">1015570</ref>
      <ref url="http://secunia.com/advisories/22065" source="SECUNIA">22065</ref>
      <ref url="http://secunia.com/advisories/18704" source="SECUNIA">18704</ref>
      <ref url="http://secunia.com/advisories/18700" source="SECUNIA">18700</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1625" source="OVAL" sig="1">oval:org.mitre.oval:def:1625</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.5" edition="beta1"/>
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition=""/>
        <vers num="1.0" edition=":alpha"/>
        <vers num="1.0" edition="beta"/>
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="1.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0300" published="2006-02-23" name="CVE-2006-0300" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Buffer overflow in tar 1.14 through 1.15.90 allows user-assisted attackers to cause a denial of service (application crash) and possibly execute code via unspecified vectors involving PAX extended headers.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-109A.html" source="CERT">TA07-109A</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA07-072A.html" source="CERT">TA07-072A</ref>
      <ref url="http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:046" source="MANDRIVA" patch="1" adv="1">MDKSA-2006:046</ref>
      <ref url="http://www.osvdb.org/23371" source="OSVDB" patch="1">23371</ref>
      <ref url="http://secunia.com/advisories/18999" source="SECUNIA" patch="1" adv="1">18999</ref>
      <ref url="http://secunia.com/advisories/18976" source="SECUNIA" patch="1" adv="1">18976</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24855" source="XF">gnu-tar-pax-headers-bo(24855)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/2518" source="VUPEN">ADV-2008-2518</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/1470" source="VUPEN">ADV-2007-1470</ref>
      <ref url="http://www.vupen.com/english/advisories/2007/0930" source="VUPEN">ADV-2007-0930</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0684" source="VUPEN">ADV-2006-0684</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-257-1" source="UBUNTU" adv="1">USN-257-1</ref>
      <ref url="http://www.trustix.org/errata/2006/0010" source="TRUSTIX" adv="1">2006-0010</ref>
      <ref url="http://www.securityfocus.com/bid/16764" source="BID">16764</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430299/100/0/threaded" source="FEDORA">FLSA:183571-2</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0232.html" source="REDHAT">RHSA-2006:0232</ref>
      <ref url="http://www.openpkg.org/security/OpenPKG-SA-2006.006-tar.html" source="OPENPKG">OpenPKG-SA-2006.006</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_05_sr.html" source="SUSE">SUSE-SR:2006:005</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200603-06.xml" source="GENTOO">GLSA-200603-06</ref>
      <ref url="http://www.debian.org/security/2006/dsa-987" source="DEBIAN">DSA-987</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-241646-1" source="SUNALERT">241646</ref>
      <ref url="http://securitytracker.com/id?1015705" source="SECTRACK">1015705</ref>
      <ref url="http://secunia.com/advisories/19236" source="SECUNIA">19236</ref>
      <ref url="http://secunia.com/advisories/19152" source="SECUNIA">19152</ref>
      <ref url="http://secunia.com/advisories/19130" source="SECUNIA">19130</ref>
      <ref url="http://secunia.com/advisories/19093" source="SECUNIA">19093</ref>
      <ref url="http://secunia.com/advisories/19016" source="SECUNIA">19016</ref>
      <ref url="http://secunia.com/advisories/18973" source="SECUNIA" adv="1">18973</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9295" source="OVAL">oval:org.mitre.oval:def:9295</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6094" source="OVAL">oval:org.mitre.oval:def:6094</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5993" source="OVAL">oval:org.mitre.oval:def:5993</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5978" source="OVAL">oval:org.mitre.oval:def:5978</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5252" source="OVAL">oval:org.mitre.oval:def:5252</ref>
      <ref url="http://lists.gnu.org/archive/html/bug-tar/2006-02/msg00051.html" source="MLIST">[Bug-tar] 20060220 tar 1.15.90 released</ref>
      <ref url="http://securityreason.com/securityalert/543" source="SREASON">543</ref>
      <ref url="http://securityreason.com/securityalert/480" source="SREASON">480</ref>
      <ref url="http://secunia.com/advisories/24966" source="SECUNIA">24966</ref>
      <ref url="http://secunia.com/advisories/24479" source="SECUNIA">24479</ref>
      <ref url="http://secunia.com/advisories/20042" source="SECUNIA">20042</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html" source="APPLE">APPLE-SA-2007-03-13</ref>
      <ref url="http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html" source="APPLE">APPLE-SA-2007-04-19</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305391" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305391</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=305214" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=305214</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="tar">
        <vers num="1.14"/>
        <vers num="1.14.1"/>
        <vers num="1.15"/>
        <vers num="1.15.1"/>
        <vers num="1.15.90"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0301" published="2006-01-30" name="CVE-2006-0301" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Splash.cc in xpdf, as used in other products such as (1) poppler, (2) kdegraphics, (3) gpdf, (4) pdfkit.framework, and others, allows attackers to cause a denial of service and possibly execute arbitrary code via crafted splash images that produce certain values that exceed the width or height of the associated bitmap.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24391" source="XF" patch="1">xpdf-splash-bo(24391)</ref>
      <ref url="http://www.ubuntu.com/usn/usn-249-1" source="UBUNTU" patch="1">USN-249-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427990/100/0/threaded" source="FEDORA" patch="1" adv="1">FLSA:175404</ref>
      <ref url="http://www.securityfocus.com/archive/1/423899/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20060202 [KDE Security Advisory] kpdf/xpdf heap based buffer overflow</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0201.html" source="REDHAT" patch="1" adv="1">RHSA-2006:0201</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-February/msg00039.html" source="FEDORA" patch="1" adv="1">FEDORA-2006-103</ref>
      <ref url="http://www.kde.org/info/security/advisory-20060202-1.txt" source="MISC" patch="1" adv="1">http://www.kde.org/info/security/advisory-20060202-1.txt</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200602-12.xml" source="GENTOO" patch="1" adv="1">GLSA-200602-12</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200602-05.xml" source="GENTOO" patch="1" adv="1">GLSA-200602-05</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200602-04.xml" source="GENTOO" patch="1" adv="1">GLSA-200602-04</ref>
      <ref url="http://www.debian.org/security/2006/dsa-974" source="DEBIAN" patch="1" adv="1">DSA-974</ref>
      <ref url="http://www.debian.org/security/2006/dsa-972" source="DEBIAN" patch="1" adv="1">DSA-972</ref>
      <ref url="http://www.debian.org/security/2006/dsa-971" source="DEBIAN" patch="1" adv="1">DSA-971</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.474747" source="SLACKWARE" patch="1">SSA:2006-045-04</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.472683" source="SLACKWARE" patch="1">SSA:2006-045-09</ref>
      <ref url="http://securitytracker.com/id?1015576" source="SECTRACK" patch="1">1015576</ref>
      <ref url="http://secunia.com/advisories/19377" source="SECUNIA" patch="1" adv="1">19377</ref>
      <ref url="http://secunia.com/advisories/18983" source="SECUNIA" patch="1" adv="1">18983</ref>
      <ref url="http://secunia.com/advisories/18913" source="SECUNIA" patch="1" adv="1">18913</ref>
      <ref url="http://secunia.com/advisories/18908" source="SECUNIA" patch="1" adv="1">18908</ref>
      <ref url="http://secunia.com/advisories/18882" source="SECUNIA" patch="1" adv="1">18882</ref>
      <ref url="http://secunia.com/advisories/18864" source="SECUNIA" patch="1" adv="1">18864</ref>
      <ref url="http://secunia.com/advisories/18862" source="SECUNIA" patch="1" adv="1">18862</ref>
      <ref url="http://secunia.com/advisories/18860" source="SECUNIA" patch="1" adv="1">18860</ref>
      <ref url="http://secunia.com/advisories/18839" source="SECUNIA" patch="1" adv="1">18839</ref>
      <ref url="http://secunia.com/advisories/18838" source="SECUNIA" patch="1" adv="1">18838</ref>
      <ref url="http://secunia.com/advisories/18837" source="SECUNIA" patch="1" adv="1">18837</ref>
      <ref url="http://secunia.com/advisories/18834" source="SECUNIA" patch="1" adv="1">18834</ref>
      <ref url="http://secunia.com/advisories/18826" source="SECUNIA" patch="1" adv="1">18826</ref>
      <ref url="http://secunia.com/advisories/18825" source="SECUNIA" patch="1" adv="1">18825</ref>
      <ref url="http://secunia.com/advisories/18707" source="SECUNIA" patch="1" adv="1">18707</ref>
      <ref url="http://secunia.com/advisories/18677" source="SECUNIA" patch="1" adv="1">18677</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2006-0206.html" source="REDHAT" patch="1" adv="1">RHSA-2006:0206</ref>
      <ref url="ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.15/SCOSA-2006.15.txt" source="SCO" patch="1" adv="1">SCOSA-2006.15</ref>
      <ref url="https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=179046" source="MISC">https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=179046</ref>
      <ref url="https://bugzilla.novell.com/show_bug.cgi?id=141242" source="CONFIRM">https://bugzilla.novell.com/show_bug.cgi?id=141242</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0422" source="VUPEN" adv="1">ADV-2006-0422</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0389" source="VUPEN" adv="1">ADV-2006-0389</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:032" source="MANDRIVA">MDKSA-2006:032</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:031" source="MANDRIVA">MDKSA-2006:031</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:030" source="MANDRIVA">MDKSA-2006:030</ref>
      <ref url="http://securityreason.com/securityalert/470" source="SREASON">470</ref>
      <ref url="http://secunia.com/advisories/18875" source="SECUNIA" adv="1">18875</ref>
      <ref url="http://secunia.com/advisories/18274" source="SECUNIA" adv="1">18274</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10850" source="OVAL">oval:org.mitre.oval:def:10850</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xpdf" name="xpdf">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0302" published="2006-01-18" name="CVE-2006-0302" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ZyXel P2000W VoIP 802.11b Wireless Phone running firmware WV.00.02 allows remote attackers to obtain sensitive information, such as MAC address and software version, by directly accessing UDP port 9090.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16285" source="BID">16285</ref>
      <ref url="http://secunia.com/advisories/18511" source="SECUNIA" adv="1">18511</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041438.html" source="FULLDISC" adv="1">20060116 ZyXel P2000W (Version 2) VoIP wireless phone undocumented port UDP/9090</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24145" source="XF">zyxel-p2000w-default-port(24145)</ref>
      <ref url="http://www.osvdb.org/22516" source="OSVDB">22516</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zyxel" name="p2000w_version_2_voip_wifi_phone">
        <vers num="wv.00.02"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0303" published="2006-01-18" name="CVE-2006-0303" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in the (1) publishing component, (2) Contact Component, (3) TinyMCE Compressor, and (4) other components in Joomla! 1.0.5 and earlier have unknown impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18513" source="SECUNIA" patch="1" adv="1">18513</ref>
      <ref url="http://www.joomla.org/content/view/738/66/" source="CONFIRM">http://www.joomla.org/content/view/738/66/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomla" name="joomla">
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0304" published="2006-01-18" name="CVE-2006-0304" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in Dual DHCP DNS Server 1.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via the DHCP options field.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18486" source="SECUNIA" patch="1" adv="1">18486</ref>
      <ref url="http://aluigi.altervista.org/adv/dualsbof-adv.txt" source="MISC" patch="1" adv="1">http://aluigi.altervista.org/adv/dualsbof-adv.txt</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0245" source="VUPEN">ADV-2006-0245</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24191" source="XF">dualdhcpdns-options-field-bo(24191)</ref>
      <ref url="http://www.securityfocus.com/bid/16298" source="BID">16298</ref>
      <ref url="http://securitytracker.com/id?1015495" source="SECTRACK">1015495</ref>
    </refs>
    <vuln_soft>
      <prod vendor="achal_dhir" name="dual_dhcp_dns_server">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0305" published="2006-01-18" name="CVE-2006-0305" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Clipcomm CPW-100E VoIP 802.11b Wireless Handset Phone running firmware 1.1.12 (051129) and CP-100E VoIP 802.11b Wireless Phone running firmware 1.1.60 allows remote attackers to gain unauthorized access via the debug service on TCP port 60023.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16289" source="BID">16289</ref>
      <ref url="http://secunia.com/advisories/18505" source="SECUNIA" adv="1">18505</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041439.html" source="FULLDISC" adv="1">20060116 Clipcomm CP-100E VoIP wireless desktop phone open debug service TCP/60023</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041436.html" source="FULLDISC" adv="1">20060116 Clipcomm CPW-100E VoIP wireless handset phone open debug service TCP/60023</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24144" source="XF">clipcomm-cp100e-default-port(24144)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clipcomm" name="cp-100e_voip_wifi_phone">
        <vers num="1.1.60"/>
      </prod>
      <prod vendor="clipcomm" name="cpw-100e_voip_wifi_phone">
        <vers num="1.1.12"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0306" published="2006-01-18" name="CVE-2006-0306" modified="2011-07-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The DM Primer (dmprimer.exe) in the DM Deployment Common Component in Computer Associates (CA) BrightStor Mobile Backup r4.0, BrightStor ARCserve Backup for Laptops &amp; Desktops r11.0, r11.1, r11.1 SP1, Unicenter Remote Control 6.0, 6.0 SP1, CA Desktop Protection Suite r2, CA Server Protection Suite r2, and CA Business Protection Suite r2 allows remote attackers to cause a denial of service (CPU consumption or application hang) via a large network packet, which causes a WSAEMESGSIZE error code that is not handled, leading to a thread exit.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=33756" source="CONFIRM" adv="1">http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=33756</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0236" source="VUPEN" adv="1">ADV-2006-0236</ref>
      <ref url="http://www.securityfocus.com/bid/16276" source="BID">16276</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422381/100/0/threaded" source="BUGTRAQ">20060118 CAID 33756 - DM Deployment Common Component Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/22529" source="OSVDB">22529</ref>
      <ref url="http://www.designfolks.com.au/karma/DMPrimer/" source="MISC" adv="1">http://www.designfolks.com.au/karma/DMPrimer/</ref>
      <ref url="http://supportconnectw.ca.com/public/ca_common_docs/dmdeploysecurity_notice.asp" source="CONFIRM" adv="1">http://supportconnectw.ca.com/public/ca_common_docs/dmdeploysecurity_notice.asp</ref>
      <ref url="http://securitytracker.com/id?1015504" source="SECTRACK">1015504</ref>
      <ref url="http://secunia.com/advisories/18531" source="SECUNIA" adv="1">18531</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="brightstor_arcserve_backup_laptops_desktops">
        <vers num="11.0"/>
        <vers num="11.1" edition="sp1"/>
      </prod>
      <prod vendor="ca" name="brightstor_mobile_backup">
        <vers num="r4.0"/>
      </prod>
      <prod vendor="ca" name="business_protection_suite">
        <vers num="2.0"/>
      </prod>
      <prod vendor="ca" name="desktop_protection_suite">
        <vers num="2.0"/>
      </prod>
      <prod vendor="ca" name="server_protection_suite">
        <vers num="2"/>
      </prod>
      <prod vendor="ca" name="unicenter_remote_control">
        <vers num="5.2"/>
        <vers num="6.0" edition="sp1"/>
        <vers num="6.0" edition="sp1:"/>
        <vers num="6.0" edition="sp1::fr"/>
        <vers num="6.0" edition="sp1::en"/>
        <vers num="6.0_build_6.0.56.3" edition=""/>
        <vers num="6.0_build_6.0.56.3" edition=":"/>
        <vers num="6.0_build_6.0.56.3" edition="::en"/>
        <vers num="6.0_build_6.0.74" edition=""/>
        <vers num="6.0_build_6.0.74" edition=":"/>
        <vers num="6.0_build_6.0.74" edition="::fr"/>
        <vers num="6.0_build_6.0.74" edition="::en"/>
        <vers num="6.0_build_6.0.74" edition="::de"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0307" published="2006-01-18" name="CVE-2006-0307" modified="2011-07-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The DM Primer in the DM Deployment Common Component in Computer Associates (CA) BrightStor Mobile Backup r4.0, BrightStor ARCserve Backup for Laptops &amp; Desktops r11.0, r11.1, r11.1 SP1, Unicenter Remote Control 6.0, 6.0 SP1, CA Desktop Protection Suite r2, CA Server Protection Suite r2, and CA Business Protection Suite r2 allows remote attackers to cause a denial of service (CPU consumption and log file consumption) via unspecified "unrecognized network messages" that are not properly handled.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1015504" source="SECTRACK" patch="1">1015504</ref>
      <ref url="http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=33756" source="CONFIRM" adv="1">http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=33756</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0236" source="VUPEN" adv="1">ADV-2006-0236</ref>
      <ref url="http://www.securityfocus.com/bid/16276" source="BID">16276</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422381/100/0/threaded" source="BUGTRAQ">20060118 CAID 33756 - DM Deployment Common Component Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/22529" source="OSVDB">22529</ref>
      <ref url="http://supportconnectw.ca.com/public/ca_common_docs/dmdeploysecurity_notice.asp" source="CONFIRM" adv="1">http://supportconnectw.ca.com/public/ca_common_docs/dmdeploysecurity_notice.asp</ref>
      <ref url="http://secunia.com/advisories/18531" source="SECUNIA" adv="1">18531</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="brightstor_arcserve_backup_laptops_desktops">
        <vers num="11.0"/>
        <vers num="11.1" edition="sp1"/>
      </prod>
      <prod vendor="ca" name="brightstor_mobile_backup">
        <vers num="r4.0"/>
      </prod>
      <prod vendor="ca" name="business_protection_suite">
        <vers num="2.0"/>
      </prod>
      <prod vendor="ca" name="desktop_protection_suite">
        <vers num="2.0"/>
      </prod>
      <prod vendor="ca" name="server_protection_suite">
        <vers num="2"/>
      </prod>
      <prod vendor="ca" name="unicenter_remote_control">
        <vers num="5.2"/>
        <vers num="6.0" edition="sp1"/>
        <vers num="6.0" edition="sp1:"/>
        <vers num="6.0" edition="sp1::fr"/>
        <vers num="6.0" edition="sp1::en"/>
        <vers num="6.0_build_6.0.56.3" edition=""/>
        <vers num="6.0_build_6.0.56.3" edition=":"/>
        <vers num="6.0_build_6.0.56.3" edition="::en"/>
        <vers num="6.0_build_6.0.74" edition=""/>
        <vers num="6.0_build_6.0.74" edition=":"/>
        <vers num="6.0_build_6.0.74" edition="::fr"/>
        <vers num="6.0_build_6.0.74" edition="::en"/>
        <vers num="6.0_build_6.0.74" edition="::de"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0308" published="2006-01-18" name="CVE-2006-0308" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in htmltonuke.php in the htmltonuke 2.0 alpha, and possibly other versions, module for PHP-Nuke allows remote attackers to execute arbitrary PHP code via a URL in the filnavn parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/33092" source="XF">htmltonuke-htmltonuke-file-include(33092)</ref>
      <ref url="http://www.securityfocus.com/bid/16282" source="BID">16282</ref>
      <ref url="http://www.milw0rm.com/exploits/3524" source="MILW0RM">3524</ref>
    </refs>
    <vuln_soft>
      <prod vendor="htmltonuke" name="htmltonuke">
        <vers num="2.0_alpha"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0309" published="2006-01-18" name="CVE-2006-0309" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:P)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Linksys BEFVP41 VPN Router 2.0 with firmware 1.01.04 allows remote attackers on the local network, to cause a denial of service via IP packets with a null IP option length.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0238" source="VUPEN">ADV-2006-0238</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422064/100/0/threaded" source="BUGTRAQ">20060116 Re: Linksys VPN Router (BEFVP41) DoS Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421929/100/0/threaded" source="BUGTRAQ">20060113 Linksys VPN Router (BEFVP41) DoS Vulnerability</ref>
      <ref url="http://securitytracker.com/id?1015490" source="SECTRACK">1015490</ref>
      <ref url="http://secunia.com/advisories/18461" source="SECUNIA" adv="1">18461</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24125" source="XF">linksys-null-length-dos(24125)</ref>
      <ref url="http://www.securityfocus.com/bid/16307" source="BID">16307</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422266/100/0/threaded" source="BUGTRAQ">20060117 Re: Linksys VPN Router (BEFVP41) DoS Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linksys" name="befvp41">
        <vers num="1.01.04"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0310" published="2006-01-18" name="CVE-2006-0310" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in aoblogger 2.3 allows remote attackers to inject arbitrary Javascript via a javascript URI in the BBcode url tag.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0240" source="VUPEN">ADV-2006-0240</ref>
      <ref url="http://www.securityfocus.com/bid/16286" source="BID">16286</ref>
      <ref url="http://secunia.com/advisories/16889" source="SECUNIA" adv="1">16889</ref>
      <ref url="http://evuln.com/vulns/37/summary.html" source="MISC" adv="1">http://evuln.com/vulns/37/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24141" source="XF">aoblogger-url-xss(24141)</ref>
      <ref url="http://www.osvdb.org/22526" source="OSVDB">22526</ref>
      <ref url="http://mikeheltonisawesome.com/viewcomments.php?idd=46" source="CONFIRM">http://mikeheltonisawesome.com/viewcomments.php?idd=46</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2006-01/0322.html" source="BUGTRAQ">20060117 [eVuln] aoblogger Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mike_helton" name="aoblogger">
        <vers num="2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0311" published="2006-01-18" name="CVE-2006-0311" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in login.php in aoblogger 2.3 allows remote attackers to execute arbitrary SQL commands via the username parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0240" source="VUPEN">ADV-2006-0240</ref>
      <ref url="http://www.securityfocus.com/bid/16286" source="BID">16286</ref>
      <ref url="http://secunia.com/advisories/16889" source="SECUNIA" adv="1">16889</ref>
      <ref url="http://evuln.com/vulns/37/summary.html" source="MISC" adv="1">http://evuln.com/vulns/37/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24142" source="XF">aoblogger-login-sql-injection(24142)</ref>
      <ref url="http://www.osvdb.org/22527" source="OSVDB">22527</ref>
      <ref url="http://mikeheltonisawesome.com/viewcomments.php?idd=46" source="CONFIRM">http://mikeheltonisawesome.com/viewcomments.php?idd=46</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2006-01/0322.html" source="BUGTRAQ">20060117 [eVuln] aoblogger Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mike_helton" name="aoblogger">
        <vers num="2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0312" published="2006-01-18" name="CVE-2006-0312" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">create.php in aoblogger 2.3 allows remote attackers to bypass authentication and create new blog entries by setting the uza parameter to 1.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0240" source="VUPEN">ADV-2006-0240</ref>
      <ref url="http://www.securityfocus.com/bid/16286" source="BID">16286</ref>
      <ref url="http://secunia.com/advisories/16889" source="SECUNIA" adv="1">16889</ref>
      <ref url="http://evuln.com/vulns/37/summary.html" source="MISC" adv="1">http://evuln.com/vulns/37/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24143" source="XF">aoblogger-create-security-bypass(24143)</ref>
      <ref url="http://mikeheltonisawesome.com/viewcomments.php?idd=46" source="CONFIRM">http://mikeheltonisawesome.com/viewcomments.php?idd=46</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2006-01/0322.html" source="BUGTRAQ">20060117 [eVuln] aoblogger Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mike_helton" name="aoblogger">
        <vers num="2.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0313" published="2006-01-18" name="CVE-2006-0313" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in PDFdirectory before 1.0 allow remote attackers to execute arbitrary SQL commands via multiple unspecified vectors involving (1) util.php, (2) userpref.php, (3) user.php, (4) uploadfrm.php, (5) title.php, (6) team.php, (7) stats.php, (8) page.php, (9) org.php, (10) member.php, (11) index.php, (12) group.php, or (13) anniv.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16273" source="BID" patch="1">16273</ref>
      <ref url="http://www.osvdb.org/22415" source="OSVDB" patch="1">22415</ref>
      <ref url="http://www.osvdb.org/22414" source="OSVDB" patch="1">22414</ref>
      <ref url="http://www.osvdb.org/22413" source="OSVDB" patch="1">22413</ref>
      <ref url="http://www.osvdb.org/22412" source="OSVDB" patch="1">22412</ref>
      <ref url="http://www.osvdb.org/22411" source="OSVDB" patch="1">22411</ref>
      <ref url="http://www.osvdb.org/22410" source="OSVDB" patch="1">22410</ref>
      <ref url="http://www.osvdb.org/22409" source="OSVDB" patch="1">22409</ref>
      <ref url="http://www.osvdb.org/22408" source="OSVDB" patch="1">22408</ref>
      <ref url="http://www.osvdb.org/22407" source="OSVDB" patch="1">22407</ref>
      <ref url="http://www.osvdb.org/22406" source="OSVDB" patch="1">22406</ref>
      <ref url="http://www.osvdb.org/22405" source="OSVDB" patch="1">22405</ref>
      <ref url="http://www.osvdb.org/22404" source="OSVDB" patch="1">22404</ref>
      <ref url="http://www.osvdb.org/22403" source="OSVDB" patch="1">22403</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=382411&amp;group_id=122682" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=382411&amp;group_id=122682</ref>
      <ref url="http://secunia.com/advisories/18459" source="SECUNIA" patch="1" adv="1">18459</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0231" source="VUPEN">ADV-2006-0231</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pdfdirectory" name="pdfdirectory">
        <vers num="0.2.10"/>
        <vers num="0.2.11"/>
        <vers num="0.2.2"/>
        <vers num="0.2.3"/>
        <vers num="0.2.4"/>
        <vers num="0.2.5"/>
        <vers num="0.2.6"/>
        <vers num="0.2.7"/>
        <vers num="0.2.8"/>
        <vers num="0.2.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0314" published="2006-01-18" name="CVE-2006-0314" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PDFdirectory before 1.0 stores sensitive data in plaintext, which allows remote attackers to obtain arbitrary users' passwords by direct queries to the database, possibly via one of the SQL injection vulnerabilities.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.osvdb.org/22402" source="OSVDB">22402</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=382411&amp;group_id=122682" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=382411&amp;group_id=122682</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pdfdirectory" name="pdfdirectory">
        <vers num="0.2.10"/>
        <vers num="0.2.11"/>
        <vers num="0.2.2"/>
        <vers num="0.2.3"/>
        <vers num="0.2.4"/>
        <vers num="0.2.5"/>
        <vers num="0.2.6"/>
        <vers num="0.2.7"/>
        <vers num="0.2.8"/>
        <vers num="0.2.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0315" published="2006-01-18" name="CVE-2006-0315" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">index.php in EZDatabase before 2.1.2 does not properly cleanse the p parameter before constructing and including a .php filename, which allows remote attackers to conduct directory traversal attacks, and produces resultant cross-site scripting (XSS) and path disclosure.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://zur.homelinux.com/Advisories/ezdatabase_dir_trans.txt" source="MISC">http://zur.homelinux.com/Advisories/ezdatabase_dir_trans.txt</ref>
      <ref url="http://www.securityfocus.com/bid/16257" source="BID">16257</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422071/100/0/threaded" source="BUGTRAQ" adv="1">20060115 EZDatabase Directory Transversal, XSS and Path Disclosure Vulnerability</ref>
      <ref url="http://secunia.com/advisories/18043" source="SECUNIA" adv="1">18043</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0515.html" source="FULLDISC" adv="1">20060115 EZDatabase Directory Transversal, XSS and Path Disclosure Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24135" source="XF">ezdatabase-index-p-path-disclosure(24135)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24134" source="XF">ezdatabase-index-p-xss(24134)</ref>
      <ref url="http://www.osvdb.org/22684" source="OSVDB">22684</ref>
    </refs>
    <vuln_soft>
      <prod vendor="indexcor" name="ezdatabase">
        <vers prev="1" num="2.1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0316" published="2006-01-18" name="CVE-2006-0316" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in YGPPicFinder.DLL in AOL You've Got Pictures (YGP) Picture Finder Tool ActiveX Control, as used in AOL 8.0, 8.0 Plus, and 9.0 Classic, allows remote attackers to execute arbitrary code via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/715730" source="CERT-VN" patch="1" adv="1">VU#715730</ref>
      <ref url="http://www.securityfocus.com/bid/16262" source="BID" patch="1">16262</ref>
      <ref url="http://secunia.com/advisories/18521" source="SECUNIA" patch="1" adv="1">18521</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24160" source="XF">aol-youvegotpictures-activex-bo(24160)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0221" source="VUPEN">ADV-2006-0221</ref>
      <ref url="http://www.osvdb.org/22486" source="OSVDB">22486</ref>
      <ref url="http://www.kb.cert.org/vuls/id/MIMG-6KRSQP" source="CONFIRM" adv="1">http://www.kb.cert.org/vuls/id/MIMG-6KRSQP</ref>
      <ref url="http://securitytracker.com/id?1015494" source="SECTRACK">1015494</ref>
      <ref url="http://news.com.com/2061-10789_3-6027865.html?part=rss&amp;tag=6027865&amp;subj=news" source="MISC">http://news.com.com/2061-10789_3-6027865.html?part=rss&amp;tag=6027865&amp;subj=news</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aol" name="aol_client_software">
        <vers num="8.0" edition=""/>
        <vers num="8.0" edition=":plus"/>
        <vers num="9.0" edition=""/>
        <vers num="9.0" edition=":classic"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0317" published="2006-01-18" name="CVE-2006-0317" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in rkrt_stats.php in RedKernel Referrer Tracker 1.1.0-3 allows remote attackers to inject arbitrary web script or HTML via a query string value as a GET, which is stored in the $QUERY_STRING variable.  NOTE: the provenance of this information is unknown; portions of the details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0197" source="VUPEN">ADV-2006-0197</ref>
      <ref url="http://www.securityfocus.com/bid/16266" source="BID">16266</ref>
      <ref url="http://secunia.com/advisories/18473" source="SECUNIA" adv="1">18473</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24151" source="XF">referertracker-rkrtstats-xss(24151)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redkernel" name="referrer_tracker">
        <vers num="1.1.0_3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0318" published="2006-01-18" name="CVE-2006-0318" modified="2011-08-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in BlogPHP 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands and bypass authentication via the username parameter in a login action.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24131" source="XF">blogphp-index-bypass-security(24131)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0204" source="VUPEN" adv="1">ADV-2006-0204</ref>
      <ref url="http://www.securityfocus.com/bid/16269" source="BID">16269</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422137/100/0/threaded" source="BUGTRAQ" adv="1">20060117 [eVuln] BlogPHP Authentication Bypass</ref>
      <ref url="http://www.osvdb.org/22495" source="OSVDB">22495</ref>
      <ref url="http://secunia.com/advisories/18467" source="SECUNIA" adv="1">18467</ref>
      <ref url="http://evuln.com/vulns/34/summary" source="MISC" adv="1">http://evuln.com/vulns/34/summary</ref>
    </refs>
    <vuln_soft>
      <prod vendor="insane_visions" name="blogphp">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0319" published="2006-01-18" name="CVE-2006-0319" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the FTP server (port 22003/tcp) in Farmers WIFE 4.4 SP1 allows remote attackers to create arbitrary files via ".." (dot dot) sequences in a (1) PUT, (2) SIZE, and possibly other commands.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.osvdb.org/22496" source="OSVDB">22496</ref>
      <ref url="http://www.lort.dk/DSR-farmerswife44sp1.pl" source="MISC">http://www.lort.dk/DSR-farmerswife44sp1.pl</ref>
      <ref url="http://secunia.com/advisories/18508" source="SECUNIA" adv="1">18508</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=113717162320654&amp;w=2" source="FULLDISC">20060113 Farmers wife 4.4 sp1 remote SYSTEM access</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24190" source="XF">farmerswife-ftp-directory-traversal(24190)</ref>
      <ref url="http://www.securityfocus.com/bid/16321" source="BID">16321</ref>
    </refs>
    <vuln_soft>
      <prod vendor="farmers_wife" name="farmers_wife">
        <vers num="4.4_sp1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0320" published="2006-01-18" name="CVE-2006-0320" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in admin/processlogin.php in Bit 5 Blog 8.01 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username and (2) password parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0195" source="VUPEN">ADV-2006-0195</ref>
      <ref url="http://www.securityfocus.com/bid/16244" source="BID">16244</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422068/100/0/threaded" source="BUGTRAQ" adv="1">20060115 [eVuln] Bit 5 Blog SQL Injection &amp; Authentication Bypass Vulnerability</ref>
      <ref url="http://secunia.com/advisories/18464" source="SECUNIA" adv="1">18464</ref>
      <ref url="http://evuln.com/vulns/31/summary" source="MISC" adv="1">http://evuln.com/vulns/31/summary</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24124" source="XF">bit5blog-processlogin-sql-injection(24124)</ref>
      <ref url="http://www.osvdb.org/22445" source="OSVDB">22445</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bit_5_blog" name="bit_5_blog">
        <vers prev="1" num="8.01"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0321" published="2006-01-23" name="CVE-2006-0321" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">fetchmail 6.3.0 and other versions before 6.3.2 allows remote attackers to cause a denial of service (crash) via crafted e-mail messages that cause a free of an invalid pointer when fetchmail bounces the message to the originator or local postmaster.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-214A.html" source="CERT">TA06-214A</ref>
      <ref url="http://fetchmail.berlios.de/fetchmail-SA-2006-01.txt" source="CONFIRM" patch="1" adv="1">http://fetchmail.berlios.de/fetchmail-SA-2006-01.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24265" source="XF">fetchmail-message-bounce-dos(24265)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3101" source="VUPEN">ADV-2006-3101</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0300" source="VUPEN">ADV-2006-0300</ref>
      <ref url="http://www.securityfocus.com/bid/19289" source="BID">19289</ref>
      <ref url="http://www.securityfocus.com/bid/16365" source="BID">16365</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422936/100/0/threaded" source="BUGTRAQ">20060122 fetchmail security announcement fetchmail-SA-2006-01 (CVE-2006-0321)</ref>
      <ref url="http://www.osvdb.org/22691" source="OSVDB">22691</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.443499" source="SLACKWARE">SSA:2006-045-01</ref>
      <ref url="http://securitytracker.com/id?1015527" source="SECTRACK">1015527</ref>
      <ref url="http://secunia.com/advisories/21253" source="SECUNIA" adv="1">21253</ref>
      <ref url="http://secunia.com/advisories/18895" source="SECUNIA" adv="1">18895</ref>
      <ref url="http://secunia.com/advisories/18571" source="SECUNIA" adv="1">18571</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006//Aug/msg00000.html" source="APPLE">APPLE-SA-2006-08-01</ref>
      <ref url="http://developer.berlios.de/project/shownotes.php?release_id=8784" source="CONFIRM">http://developer.berlios.de/project/shownotes.php?release_id=8784</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=348747" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=348747</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fetchmail" name="fetchmail">
        <vers num="6.3.0"/>
        <vers num="6.3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0322" published="2006-01-19" name="CVE-2006-0322" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability the edit comment formatting functionality in MediaWiki 1.5.x before 1.5.6 and 1.4.x before 1.4.14 allows attackers to cause a denial of service (infinite loop) via "certain malformed links."</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=386609" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=386609</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0392" source="VUPEN">ADV-2006-0392</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24478" source="XF">mediawiki-comment-format-dos(24478)</ref>
      <ref url="http://secunia.com/advisories/18717" source="SECUNIA">18717</ref>
      <ref url="http://secunia.com/advisories/18711" source="SECUNIA">18711</ref>
      <ref url="http://lists.suse.com/archive/suse-security-announce/2006-Feb/0001.html" source="SUSE">SUSE-SR:2006:003</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mediawiki" name="mediawiki">
        <vers num="1.4.1"/>
        <vers num="1.4.10"/>
        <vers num="1.4.11"/>
        <vers num="1.4.12"/>
        <vers num="1.4.13"/>
        <vers num="1.4.14"/>
        <vers num="1.4.2"/>
        <vers num="1.4.3"/>
        <vers num="1.4.4"/>
        <vers num="1.4.5"/>
        <vers num="1.4.6"/>
        <vers num="1.4.7"/>
        <vers num="1.4.8"/>
        <vers num="1.4.9"/>
        <vers num="1.4_beta1"/>
        <vers num="1.4_beta2"/>
        <vers num="1.4_beta3"/>
        <vers num="1.4_beta4"/>
        <vers num="1.4_beta5"/>
        <vers num="1.4_beta6"/>
        <vers num="1.5.0"/>
        <vers num="1.5.1"/>
        <vers num="1.5.2"/>
        <vers num="1.5.3"/>
        <vers num="1.5.4"/>
        <vers num="1.5.5"/>
        <vers num="1.5_alpha1"/>
        <vers num="1.5_alpha2"/>
        <vers num="1.5_beta1"/>
        <vers num="1.5_beta2"/>
        <vers num="1.5_beta3"/>
        <vers num="1.5_beta4"/>
        <vers num="1.5_rc2"/>
        <vers num="1.5_rc3"/>
        <vers num="1.5_rc4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0323" published="2006-03-23" name="CVE-2006-0323" modified="2011-03-07" discovered="2005-10-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in swfformat.dll in multiple RealNetworks products and versions including RealPlayer 10.x, RealOne Player, Rhapsody 3, and Helix Player allows remote attackers to execute arbitrary code via a crafted SWF (Flash) file with (1) a a size value that is less than the actual size, or (2) other unspecified manipulations.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/231028" source="CERT-VN" patch="1" adv="1">VU#231028</ref>
      <ref url="http://www.service.real.com/realplayer/security/03162006_player/en/" source="CONFIRM" patch="1">http://www.service.real.com/realplayer/security/03162006_player/en/</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0257.html" source="REDHAT" patch="1" adv="1">RHSA-2006:0257</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_18_realplayer.html" source="SUSE" patch="1" adv="1">SUSE-SA:2006:018</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200603-24.xml" source="GENTOO" patch="1" adv="1">GLSA-200603-24</ref>
      <ref url="http://secunia.com/advisories/19365" source="SECUNIA" patch="1" adv="1">19365</ref>
      <ref url="http://secunia.com/advisories/19362" source="SECUNIA" patch="1" adv="1">19362</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25408" source="XF">realnetworks-swf-bo(25408)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1057" source="VUPEN">ADV-2006-1057</ref>
      <ref url="http://www.securityfocus.com/bid/17202" source="BID">17202</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/430621/100/0/threaded" source="BUGTRAQ">20060411 Realplayer .SWF Multiple Remote Memory Corruption Vulnerabilities</ref>
      <ref url="http://securitytracker.com/id?1015806" source="SECTRACK">1015806</ref>
      <ref url="http://securityreason.com/securityalert/690" source="SREASON">690</ref>
      <ref url="http://secunia.com/advisories/19390" source="SECUNIA" adv="1">19390</ref>
      <ref url="http://secunia.com/advisories/19358" source="SECUNIA" adv="1">19358</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realnetworks" name="helix_player">
        <vers num=""/>
      </prod>
      <prod vendor="realnetworks" name="realone_player">
        <vers num=""/>
      </prod>
      <prod vendor="realnetworks" name="realplayer">
        <vers num="10.0" edition="gold"/>
        <vers num="10.0.6"/>
        <vers num="10.5"/>
      </prod>
      <prod vendor="realnetworks" name="rhapsody">
        <vers num="3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0324" published="2006-01-19" name="CVE-2006-0324" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in WebspotBlogging 3.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the username parameter to login.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0268" source="VUPEN">ADV-2006-0268</ref>
      <ref url="http://www.securityfocus.com/bid/16319" source="BID">16319</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422364/100/0/threaded" source="BUGTRAQ" adv="1">20060119 [eVuln] WebspotBlogging Authentication Bypass Vulnerability</ref>
      <ref url="http://evuln.com/vulns/41/summary.html" source="MISC" adv="1">http://evuln.com/vulns/41/summary.html</ref>
      <ref url="https://sourceforge.net/project/shownotes.php?release_id=387180&amp;group_id=156586" source="CONFIRM">https://sourceforge.net/project/shownotes.php?release_id=387180&amp;group_id=156586</ref>
      <ref url="https://sourceforge.net/forum/forum.php?forum_id=532233" source="CONFIRM">https://sourceforge.net/forum/forum.php?forum_id=532233</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24222" source="XF">webspotblogging-login-sql-injection(24222)</ref>
      <ref url="http://www.osvdb.org/22670" source="OSVDB">22670</ref>
      <ref url="http://securitytracker.com/id?1015522" source="SECTRACK">1015522</ref>
      <ref url="http://securityreason.com/securityalert/356" source="SREASON">356</ref>
      <ref url="http://secunia.com/advisories/18560" source="SECUNIA">18560</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webspot" name="webspotblogging">
        <vers num="3.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0325" published="2006-01-20" name="CVE-2006-0325" modified="2011-12-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Etomite Content Management System 0.6, and possibly earlier versions, when downloaded from the web site in January 2006 after January 10, contains a back door in manager/includes/todo.inc.php, which allows remote attackers to execute arbitrary commands via the "cij" parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24254" source="XF" patch="1">etomite-default-backdoor(24254)</ref>
      <ref url="http://secunia.com/advisories/18556" source="SECUNIA" patch="1" adv="1">18556</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0283" source="VUPEN">ADV-2006-0283</ref>
      <ref url="http://www.securityfocus.com/bid/16336" source="BID">16336</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423523/100/0/threaded" source="BUGTRAQ">20060130 Etomite followup information</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423497/100/0/threaded" source="BUGTRAQ">20060127 Etomite CMS </ref>
      <ref url="http://www.osvdb.org/22693" source="OSVDB">22693</ref>
      <ref url="http://www.lucaercoli.it/advs/etomite.txt" source="MISC">http://www.lucaercoli.it/advs/etomite.txt</ref>
      <ref url="http://www.etomite.org/forums/index.php?showtopic=4291" source="CONFIRM">http://www.etomite.org/forums/index.php?showtopic=4291</ref>
      <ref url="http://www.etomite.org/forums/index.php?showtopic=4185" source="CONFIRM">http://www.etomite.org/forums/index.php?showtopic=4185</ref>
    </refs>
    <vuln_soft>
      <prod vendor="etomite" name="etomite">
        <vers prev="1" num="0.6"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0327" published="2006-01-20" name="CVE-2006-0327" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">TYPO3 3.7.1 allows remote attackers to obtain sensitive information via a direct request to (1) thumbs.php, (2) showpic.php, or (3) tables.php, which causes them to incorrectly define a variable and reveal the path in an error message when a require function call fails.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422360/100/0/threaded" source="BUGTRAQ" patch="1">20060119 IRM 015: File system path disclosure on TYPO3 Web Content Manager</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0269" source="VUPEN">ADV-2006-0269</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422390/100/0/threaded" source="BUGTRAQ">20060119 Re: IRM 015: File system path disclosure on TYPO3 Web Content Manager</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422390/100/0/threaded" source="BUGTRAQ">20060119 Re: IRM 015: File system path disclosure on TYPO3 Web Content Manage</ref>
      <ref url="http://www.irmplc.com/advisory015.htm" source="MISC" adv="1">http://www.irmplc.com/advisory015.htm</ref>
      <ref url="http://secunia.com/advisories/18546" source="SECUNIA" adv="1">18546</ref>
      <ref url="http://bugs.typo3.org/view.php?id=2248" source="MISC">http://bugs.typo3.org/view.php?id=2248</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24244" source="XF">typo3-multiple-path-disclosure(24244)</ref>
      <ref url="http://www.osvdb.org/22667" source="OSVDB">22667</ref>
      <ref url="http://www.osvdb.org/22666" source="OSVDB">22666</ref>
      <ref url="http://www.osvdb.org/22665" source="OSVDB">22665</ref>
      <ref url="http://securityreason.com/securityalert/361" source="SREASON">361</ref>
    </refs>
    <vuln_soft>
      <prod vendor="typo3" name="typo3">
        <vers num="3.7.1"/>
        <vers num="3.8.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0328" published="2006-01-20" name="CVE-2006-0328" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Format string vulnerability in Tftpd32 2.81 allows remote attackers to cause a denial of service via format string specifiers in a filename in a (1) GET or (2) SEND request.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/632633" source="CERT-VN">VU#632633</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0263" source="VUPEN">ADV-2006-0263</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422405/100/0/threaded" source="BUGTRAQ" adv="1">20060119 Critical security advisory #006 tftpd32 Format string</ref>
      <ref url="http://www.critical.lt/research/tftpd32_281_dos.txt" source="MISC">http://www.critical.lt/research/tftpd32_281_dos.txt</ref>
      <ref url="http://www.critical.lt/?vulnerabilities/200" source="MISC" adv="1">http://www.critical.lt/?vulnerabilities/200</ref>
      <ref url="http://secunia.com/advisories/18539" source="SECUNIA" adv="1">18539</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24250" source="XF">tftpd32-request-format-string(24250)</ref>
      <ref url="http://www.securityfocus.com/bid/16333" source="BID">16333</ref>
      <ref url="http://www.osvdb.org/22661" source="OSVDB">22661</ref>
      <ref url="http://securityreason.com/securityalert/362" source="SREASON">362</ref>
    </refs>
    <vuln_soft>
      <prod vendor="philippe_jounin" name="tftpd32">
        <vers num="2.81"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0329" published="2006-01-20" name="CVE-2006-0329" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in HITSENSER Data Mart Server BS, BS-S, BS-M, BS-L, and EX allows remote attackers to execute arbitrary SQL commands via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18553" source="SECUNIA" patch="1" adv="1">18553</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0266" source="VUPEN">ADV-2006-0266</ref>
      <ref url="http://www.securityfocus.com/bid/16326" source="BID">16326</ref>
      <ref url="http://www.osvdb.org/22669" source="OSVDB">22669</ref>
      <ref url="http://www.hitachi-support.com/security_e/vuls_e/HS05-026_e/index-e.html" source="CONFIRM">http://www.hitachi-support.com/security_e/vuls_e/HS05-026_e/index-e.html</ref>
      <ref url="http://securitytracker.com/id?1015519" source="SECTRACK">1015519</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24240" source="XF">hitachi-hitsenser-sql-injection(24240)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hitachi" name="hitsenser_data_mart_server">
        <vers num="bs"/>
        <vers num="bs_l"/>
        <vers num="bs_m"/>
        <vers num="bs_s"/>
        <vers num="ex"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0330" published="2006-01-20" name="CVE-2006-0330" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Gallery before 1.5.2 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors, possibly involving the user name (fullname).</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24247" source="XF" patch="1">gallery-unknown-xss(24247)</ref>
      <ref url="http://www.securityfocus.com/bid/16334" source="BID" patch="1">16334</ref>
      <ref url="http://www.osvdb.org/22660" source="OSVDB" patch="1">22660</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200601-13.xml" source="GENTOO" patch="1" adv="1">GLSA-200601-13</ref>
      <ref url="http://secunia.com/advisories/18627" source="SECUNIA" patch="1" adv="1">18627</ref>
      <ref url="http://secunia.com/advisories/18557" source="SECUNIA" patch="1" adv="1">18557</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0282" source="VUPEN">ADV-2006-0282</ref>
      <ref url="http://gallery.menalto.com/page/gallery_1_5_2_release" source="CONFIRM">http://gallery.menalto.com/page/gallery_1_5_2_release</ref>
      <ref url="http://www.us.debian.org/security/2006/dsa-1148" source="DEBIAN">DSA-1148</ref>
      <ref url="http://secunia.com/advisories/21502" source="SECUNIA">21502</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=325285" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=325285</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gallery_project" name="gallery">
        <vers num="1.3.4"/>
        <vers num="1.4"/>
        <vers num="1.4.1"/>
        <vers num="1.4.2"/>
        <vers num="1.4.3_pl1"/>
        <vers num="1.4.3_pl2"/>
        <vers num="1.4.4_pl2"/>
        <vers num="1.4.4_pl3"/>
        <vers num="1.4.4_pl4"/>
        <vers num="1.4.4_pl5"/>
        <vers num="1.4_pl1"/>
        <vers num="1.4_pl2"/>
        <vers num="1.5"/>
        <vers num="1.5.1"/>
        <vers num="1.5.1_rc2"/>
        <vers num="1.5.2_rc2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0331" published="2006-01-20" name="CVE-2006-0331" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Buffer overflow in Change passwd 3.1 (chpasswd) SquirrelMail plugin allows local users to execute arbitrary code via long command line arguments.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.squirrelmail.org/plugin_view.php?id=117" source="MISC">http://www.squirrelmail.org/plugin_view.php?id=117</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422414/100/0/threaded" source="BUGTRAQ">20060119 Change passwd 3.1 (SquirrelMail plugin )</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24258" source="XF">changepassword-changepasswd-bo(24258)</ref>
      <ref url="http://securityreason.com/securityalert/363" source="SREASON">363</ref>
    </refs>
    <vuln_soft>
      <prod vendor="thiago_melo_de_paula" name="change_passwd">
        <vers num="3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0332" published="2006-01-20" name="CVE-2006-0332" modified="2011-08-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Pantomime in Ecartis 1.0.0 snapshot 20050909 stores e-mail attachments in a publicly accessible directory, which may allow remote attackers to upload arbitrary files.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16317" source="BID" patch="1">16317</ref>
      <ref url="http://secunia.com/advisories/18524" source="SECUNIA" patch="1" adv="1">18524</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24220" source="XF">ecartis-pantomime-bypass-security(24220)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0260" source="VUPEN" adv="1">ADV-2006-0260</ref>
      <ref url="http://marc.theaimsgroup.com/?l=listar-dev&amp;m=113770802408358&amp;w=2" source="MLIST">[listar-dev] 20060119 [EDev] Re: Potential vulnerability -- who to contact?</ref>
      <ref url="http://marc.theaimsgroup.com/?l=listar-dev&amp;m=113732552708625&amp;w=2" source="MLIST">[listar-dev] 20060115 [EDev] Re: Potential vulnerability -- who to contact?</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ecartis" name="ecartis">
        <vers num="1.0.0_snapshot_2005-09-09"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0333" published="2006-01-20" name="CVE-2006-0333" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in ar-blog 5.2 allows remote attackers to inject arbitrary web script or HTML via the (1) month or (2) year parameter to index.php.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422386/100/0/threaded" source="BUGTRAQ" adv="1">20060118 -2- [XSS] in ar-blog v 5.2</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24246" source="XF">arblog-index-xss(24246)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/435205/100/0/threaded" source="BUGTRAQ">20060527 Multiple Xss exploits in ar-blog v 5.2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ar-blog" name="ar-blog">
        <vers num="5.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0334" published="2006-01-20" name="CVE-2006-0334" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in search.php in My Amazon Store Manager 1.0 allows remote attackers to inject arbitrary web script or HTML via the Keywords parameter.  NOTE: some sources claim that the affected parameter is "q", but the only public archive of the original researcher notification shows an XSS manipulation in "Keywords".</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24230" source="XF">masm-search-xss(24230)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0252" source="VUPEN">ADV-2006-0252</ref>
      <ref url="http://www.securityfocus.com/bid/16312" source="BID">16312</ref>
      <ref url="http://www.osvdb.org/22626" source="OSVDB">22626</ref>
      <ref url="http://secunia.com/advisories/18535" source="SECUNIA" adv="1">18535</ref>
      <ref url="http://osvdb.org/ref/22/22626-my_amazon.txt" source="MISC">http://osvdb.org/ref/22/22626-my_amazon.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freekrai.net" name="my_amazon_store_manager">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0335" published="2006-01-20" name="CVE-2006-0335" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Kerio WinRoute Firewall before 6.1.4 Patch 1 allow remote attackers to cause a denial of service via multiple unspecified vectors involving (1) long strings received from Active Directory and (2) the filtering of HTML.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16314" source="BID" patch="1">16314</ref>
      <ref url="http://www.osvdb.org/22631" source="OSVDB" patch="1">22631</ref>
      <ref url="http://secunia.com/advisories/18542" source="SECUNIA" patch="1" adv="1">18542</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24233" source="XF">kerio-winroute-activedirectory-dos(24233)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24232" source="XF">kerio-winroute-html-dos(24232)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0247" source="VUPEN">ADV-2006-0247</ref>
      <ref url="http://www.kerio.com/kwf_history.html" source="CONFIRM">http://www.kerio.com/kwf_history.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kerio" name="winroute_firewall">
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4"/>
        <vers num="5.0.5"/>
        <vers num="5.0.6"/>
        <vers num="5.0.7"/>
        <vers num="5.0.8"/>
        <vers num="5.0.9"/>
        <vers num="5.1"/>
        <vers num="5.1.1"/>
        <vers num="5.1.10"/>
        <vers num="5.1.2"/>
        <vers num="5.1.3"/>
        <vers num="5.1.4"/>
        <vers num="5.1.5"/>
        <vers num="5.1.6"/>
        <vers num="5.1.7"/>
        <vers num="5.1.8"/>
        <vers num="5.1.9"/>
        <vers num="5.10"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.10"/>
        <vers num="6.0.11"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
        <vers num="6.0.5"/>
        <vers num="6.0.6"/>
        <vers num="6.0.7"/>
        <vers num="6.0.8"/>
        <vers num="6.0.9"/>
        <vers num="6.1.0"/>
        <vers num="6.1.1"/>
        <vers num="6.1.2"/>
        <vers num="6.1.3"/>
        <vers num="6.1.3_patch1"/>
        <vers num="6.1.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0336" published="2006-01-20" name="CVE-2006-0336" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Kerio WinRoute Firewall before 6.1.4 Patch 2 allows attackers to cause a denial of service (CPU consumption and hang) via unknown vectors involving "browsing the web".</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0324" source="VUPEN">ADV-2006-0324</ref>
      <ref url="http://www.kerio.com/kwf_history.html" source="CONFIRM">http://www.kerio.com/kwf_history.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24317" source="XF">kerio-winroute-browsing-dos(24317)</ref>
      <ref url="http://www.securityfocus.com/bid/16385" source="BID">16385</ref>
      <ref url="http://www.osvdb.org/22631" source="OSVDB">22631</ref>
      <ref url="http://secunia.com/advisories/18589" source="SECUNIA">18589</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kerio" name="winroute_firewall">
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4"/>
        <vers num="5.0.5"/>
        <vers num="5.0.6"/>
        <vers num="5.0.7"/>
        <vers num="5.0.8"/>
        <vers num="5.0.9"/>
        <vers num="5.1"/>
        <vers num="5.1.1"/>
        <vers num="5.1.10"/>
        <vers num="5.1.2"/>
        <vers num="5.1.3"/>
        <vers num="5.1.4"/>
        <vers num="5.1.5"/>
        <vers num="5.1.6"/>
        <vers num="5.1.7"/>
        <vers num="5.1.8"/>
        <vers num="5.1.9"/>
        <vers num="5.10"/>
        <vers num="6.0.0"/>
        <vers num="6.0.1"/>
        <vers num="6.0.10"/>
        <vers num="6.0.11"/>
        <vers num="6.0.2"/>
        <vers num="6.0.3"/>
        <vers num="6.0.4"/>
        <vers num="6.0.5"/>
        <vers num="6.0.6"/>
        <vers num="6.0.7"/>
        <vers num="6.0.8"/>
        <vers num="6.0.9"/>
        <vers num="6.1.0"/>
        <vers num="6.1.1"/>
        <vers num="6.1.2"/>
        <vers num="6.1.3"/>
        <vers num="6.1.3_patch1"/>
        <vers num="6.1.4"/>
        <vers num="6.1.4_patch_1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0337" published="2006-01-20" name="CVE-2006-0337" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in multiple F-Secure Anti-Virus products and versions for Windows and Linux, including Anti-Virus for Windows Servers 5.52 and earlier, Internet Security 2004, 2005 and 2006, and Anti-Virus for Linux Servers 4.64 and earlier, allows remote attackers to execute arbitrary code via crafted ZIP archives.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.f-secure.com/security/fsc-2006-1.shtml" source="CONFIRM" patch="1" adv="1">http://www.f-secure.com/security/fsc-2006-1.shtml</ref>
      <ref url="http://secunia.com/advisories/18529" source="SECUNIA" patch="1" adv="1">18529</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0257" source="VUPEN">ADV-2006-0257</ref>
      <ref url="http://www.securityfocus.com/bid/16309" source="BID">16309</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24198" source="XF">fsecure-zip-bo(24198)</ref>
      <ref url="http://www.osvdb.org/22632" source="OSVDB">22632</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/q-103.shtml" source="CIAC">Q-103</ref>
      <ref url="http://securitytracker.com/id?1015510" source="SECTRACK">1015510</ref>
      <ref url="http://securitytracker.com/id?1015509" source="SECTRACK">1015509</ref>
      <ref url="http://securitytracker.com/id?1015508" source="SECTRACK">1015508</ref>
      <ref url="http://securitytracker.com/id?1015507" source="SECTRACK">1015507</ref>
    </refs>
    <vuln_soft>
      <prod vendor="f-secure" name="f-secure_anti-virus">
        <vers num="2.16" edition=""/>
        <vers num="2.16" edition=":linux_gateways"/>
        <vers num="2004"/>
        <vers num="2005"/>
        <vers num="2006"/>
        <vers num="4.51" edition=""/>
        <vers num="4.51" edition=":linux_workstations"/>
        <vers num="4.51" edition=":linux_servers"/>
        <vers num="4.51" edition=":linux_gateways"/>
        <vers num="4.52" edition=""/>
        <vers num="4.52" edition=":linux_workstations"/>
        <vers num="4.52" edition=":linux_servers"/>
        <vers num="4.52" edition=":linux_gateways"/>
        <vers num="4.61" edition=""/>
        <vers num="4.61" edition=":linux_gateways"/>
        <vers num="4.61" edition=":linux_servers"/>
        <vers num="4.62" edition=""/>
        <vers num="4.62" edition=":samba_servers"/>
        <vers num="4.64" edition=""/>
        <vers num="4.64" edition=":linux_gateways"/>
        <vers num="4.64" edition=":linux_servers"/>
        <vers num="5.0" edition=""/>
        <vers num="5.0" edition=":linux_server_security"/>
        <vers num="5.0" edition=":linux_client_security"/>
        <vers num="5.01" edition=""/>
        <vers num="5.01" edition=":linux_client_security"/>
        <vers num="5.01" edition=":linux_server_security"/>
        <vers num="5.11" edition=""/>
        <vers num="5.11" edition=":linux_client_security"/>
        <vers num="5.11" edition=":linux_server_security"/>
        <vers num="5.40" edition=""/>
        <vers num="5.40" edition=":workstations"/>
        <vers num="5.41" edition=""/>
        <vers num="5.41" edition=":mimesweeper"/>
        <vers num="5.41" edition=":workstations"/>
        <vers num="5.41" edition=":windows_servers"/>
        <vers num="5.42" edition=""/>
        <vers num="5.42" edition=":mimesweeper"/>
        <vers num="5.42" edition=":windows_servers"/>
        <vers num="5.42" edition=":workstations"/>
        <vers num="5.43" edition=""/>
        <vers num="5.43" edition=":workstations"/>
        <vers num="5.44" edition=""/>
        <vers num="5.44" edition=":workstations"/>
        <vers num="5.5" edition=""/>
        <vers num="5.5" edition=":client_security"/>
        <vers num="5.5" edition=":mimesweeper"/>
        <vers num="5.5" edition=":windows_servers"/>
        <vers num="5.5" edition=":citrix_servers"/>
        <vers num="5.51" edition=""/>
        <vers num="5.51" edition=":mimesweeper"/>
        <vers num="5.52" edition=""/>
        <vers num="5.52" edition=":citrix_servers"/>
        <vers num="5.52" edition=":client_security"/>
        <vers num="5.52" edition=":windows_servers"/>
        <vers num="5.54" edition=""/>
        <vers num="5.54" edition=":client_security"/>
        <vers num="5.55" edition=""/>
        <vers num="5.55" edition=":client_security"/>
        <vers num="5.61" edition=""/>
        <vers num="5.61" edition=":mimesweeper"/>
        <vers num="6.01" edition=""/>
        <vers num="6.01" edition=":ms_exchange"/>
        <vers num="6.01" edition=":client_security"/>
        <vers num="6.2" edition=""/>
        <vers num="6.2" edition=":ms_exchange"/>
        <vers num="6.2" edition=":firewalls"/>
        <vers num="6.21" edition=""/>
        <vers num="6.21" edition=":ms_exchange"/>
        <vers num="6.30" edition=""/>
        <vers num="6.30" edition=":ms_exchange"/>
        <vers num="6.30_sr1" edition=""/>
        <vers num="6.30_sr1" edition=":ms_exchange"/>
        <vers num="6.31" edition=""/>
        <vers num="6.31" edition=":ms_exchange"/>
        <vers num="6.40" edition=""/>
        <vers num="6.40" edition=":ms_exchange"/>
      </prod>
      <prod vendor="f-secure" name="f-secure_internet_security">
        <vers num="2004"/>
        <vers num="2005"/>
        <vers num="2006"/>
      </prod>
      <prod vendor="f-secure" name="internet_gatekeeper">
        <vers num="2.06" edition=""/>
        <vers num="2.06" edition=":linux"/>
        <vers num="2.14" edition=""/>
        <vers num="2.14" edition=":linux"/>
        <vers num="2.6" edition=""/>
        <vers num="2.6" edition=":linux"/>
        <vers num="6.3"/>
        <vers num="6.31"/>
        <vers num="6.32"/>
        <vers num="6.4"/>
        <vers num="6.41"/>
        <vers num="6.42"/>
      </prod>
      <prod vendor="f-secure" name="solutions_based_on_f-secure_personal_express">
        <vers num="6.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0338" published="2006-01-20" name="CVE-2006-0338" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple F-Secure Anti-Virus products and versions for Windows and Linux, including Anti-Virus for Windows Servers 5.52 and earlier, Internet Security 2004, 2005 and 2006, and Anti-Virus for Linux Servers 4.64 and earlier, allow remote attackers to hide arbitrary files and data via malformed (1) RAR and (2) ZIP archives, which are not properly scanned.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16309" source="BID" patch="1">16309</ref>
      <ref url="http://www.f-secure.com/security/fsc-2006-1.shtml" source="CONFIRM" patch="1">http://www.f-secure.com/security/fsc-2006-1.shtml</ref>
      <ref url="http://secunia.com/advisories/18529" source="SECUNIA" patch="1" adv="1">18529</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0257" source="VUPEN">ADV-2006-0257</ref>
      <ref url="http://www.osvdb.org/22633" source="OSVDB">22633</ref>
      <ref url="http://www.ciac.org/ciac/bulletins/q-103.shtml" source="CIAC">Q-103</ref>
      <ref url="http://securitytracker.com/id?1015510" source="SECTRACK">1015510</ref>
      <ref url="http://securitytracker.com/id?1015509" source="SECTRACK">1015509</ref>
      <ref url="http://securitytracker.com/id?1015508" source="SECTRACK">1015508</ref>
      <ref url="http://securitytracker.com/id?1015507" source="SECTRACK">1015507</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24199" source="XF">fsecure-rar-zip-scan-bypass(24199)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="f-secure" name="f-secure_anti-virus">
        <vers num="2003"/>
        <vers num="2004"/>
        <vers num="2005"/>
        <vers num="4.51" edition=""/>
        <vers num="4.51" edition=":linux_servers"/>
        <vers num="4.51" edition=":linux_gateways"/>
        <vers num="4.52" edition=""/>
        <vers num="4.52" edition=":linux_workstations"/>
        <vers num="4.52" edition=":linux_servers"/>
        <vers num="4.52" edition=":linux_gateways"/>
        <vers num="4.60" edition=""/>
        <vers num="4.60" edition=":samba_servers"/>
        <vers num="4.61" edition=""/>
        <vers num="4.61" edition=":linux_gateways"/>
        <vers num="4.61" edition=":linux_servers"/>
        <vers num="4.62" edition=""/>
        <vers num="4.62" edition=":samba_servers"/>
        <vers num="4.64" edition=""/>
        <vers num="4.64" edition=":linux_gateways"/>
        <vers num="4.64" edition=":linux_servers"/>
        <vers num="5.0" edition=""/>
        <vers num="5.0" edition=":linux_server_security"/>
        <vers num="5.0" edition=":linux_client_security"/>
        <vers num="5.11" edition=""/>
        <vers num="5.11" edition=":linux_client_security"/>
        <vers num="5.11" edition=":linux_server_security"/>
        <vers num="5.41" edition=""/>
        <vers num="5.41" edition=":mimesweeper"/>
        <vers num="5.41" edition=":workstations"/>
        <vers num="5.42" edition=""/>
        <vers num="5.42" edition=":mimesweeper"/>
        <vers num="5.42" edition=":windows_servers"/>
        <vers num="5.42" edition=":workstations"/>
        <vers num="5.43" edition=""/>
        <vers num="5.43" edition=":workstations"/>
        <vers num="5.44" edition=""/>
        <vers num="5.44" edition=":workstations"/>
        <vers num="5.5" edition=""/>
        <vers num="5.5" edition=":client_security"/>
        <vers num="5.5" edition=":mimesweeper"/>
        <vers num="5.5" edition=":windows_servers"/>
        <vers num="5.52" edition=""/>
        <vers num="5.52" edition=":mimesweeper"/>
        <vers num="5.52" edition=":citrix_servers"/>
        <vers num="5.52" edition=":client_security"/>
        <vers num="5.52" edition=":windows_servers"/>
        <vers num="5.55" edition=""/>
        <vers num="5.55" edition=":client_security"/>
        <vers num="6.01" edition=""/>
        <vers num="6.01" edition=":ms_exchange"/>
        <vers num="6.01" edition=":client_security"/>
        <vers num="6.2" edition=""/>
        <vers num="6.2" edition=":ms_exchange"/>
        <vers num="6.2" edition=":firewalls"/>
        <vers num="6.21" edition=""/>
        <vers num="6.21" edition=":ms_exchange"/>
        <vers num="6.30" edition=""/>
        <vers num="6.30" edition=":ms_exchange"/>
        <vers num="6.30_sr1" edition=""/>
        <vers num="6.30_sr1" edition=":ms_exchange"/>
        <vers num="6.31" edition=""/>
        <vers num="6.31" edition=":ms_exchange"/>
        <vers num="6.40" edition=""/>
        <vers num="6.40" edition=":ms_exchange"/>
      </prod>
      <prod vendor="f-secure" name="f-secure_internet_security">
        <vers num="2004"/>
        <vers num="2005"/>
        <vers num="2006"/>
      </prod>
      <prod vendor="f-secure" name="f-secure_personal_express">
        <vers num="4.5"/>
        <vers num="4.6"/>
        <vers num="4.7"/>
        <vers num="5.0"/>
      </prod>
      <prod vendor="f-secure" name="internet_gatekeeper">
        <vers num="2.06" edition=""/>
        <vers num="2.06" edition=":linux"/>
        <vers num="2.14" edition=""/>
        <vers num="2.14" edition=":linux"/>
        <vers num="6.32"/>
        <vers num="6.41"/>
        <vers num="6.42"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0339" published="2006-01-20" name="CVE-2006-0339" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in BitComet Client 0.60 allows remote attackers to execute arbitrary code, when the publisher's name link is clicked, via a long publisher URI in a torrent file.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16311" source="BID" patch="1">16311</ref>
      <ref url="http://secunia.com/advisories/18522" source="SECUNIA" patch="1" adv="1">18522</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0251" source="VUPEN">ADV-2006-0251</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422361/100/0/threaded" source="BUGTRAQ" adv="1">20060118 Fortinet Advisory: BitComet URI Buffer Overflow Vulnerability</ref>
      <ref url="http://www.fortinet.com/FortiGuardCenter/FSA-2006-07.html" source="MISC" adv="1">http://www.fortinet.com/FortiGuardCenter/FSA-2006-07.html</ref>
      <ref url="http://www.bitcomet.com/doc/changelog.htm" source="CONFIRM">http://www.bitcomet.com/doc/changelog.htm</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24229" source="XF">bitcomet-torrent-publisher-bo(24229)</ref>
      <ref url="http://www.osvdb.org/22625" source="OSVDB">22625</ref>
      <ref url="http://securityreason.com/securityalert/357" source="SREASON">357</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0669.html" source="FULLDISC">20060118 Fortinet Advisory: BitComet URI Buffer Overflow Vulnerability</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2006-01/0442.html" source="BUGTRAQ">20060122 BitComet URI Proof of Concept</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bitcomet" name="bitcomet">
        <vers num="0.60"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0340" published="2006-01-20" name="CVE-2006-0340" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in Stack Group Bidding Protocol (SGBP) support in Cisco IOS 12.0 through 12.4 running on various Cisco products, when SGBP is enabled, allows remote attackers on the local network to cause a denial of service (device hang and network traffic loss) via a crafted UDP packet to port 9900.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1015501" source="SECTRACK" patch="1">1015501</ref>
      <ref url="http://secunia.com/advisories/18490" source="SECUNIA" patch="1" adv="1">18490</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24182" source="XF">cisco-ios-sgbp-dos(24182)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0248" source="VUPEN">ADV-2006-0248</ref>
      <ref url="http://www.securityfocus.com/bid/16303" source="BID">16303</ref>
      <ref url="http://www.osvdb.org/22624" source="OSVDB">22624</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20060118-sgbp.shtml" source="CISCO" adv="1">20060118 IOS Stack Group Bidding Protocol Crafted Packet DoS</ref>
      <ref url="http://securityreason.com/securityalert/358" source="SREASON">358</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.0"/>
        <vers num="12.0s"/>
        <vers num="12.0sc"/>
        <vers num="12.0t"/>
        <vers num="12.0xa"/>
        <vers num="12.0xc"/>
        <vers num="12.0xd"/>
        <vers num="12.0xe"/>
        <vers num="12.0xg"/>
        <vers num="12.0xh"/>
        <vers num="12.0xi"/>
        <vers num="12.0xj"/>
        <vers num="12.0xk"/>
        <vers num="12.0xl"/>
        <vers num="12.0xn"/>
        <vers num="12.0xr"/>
        <vers num="12.1"/>
        <vers num="12.1aa"/>
        <vers num="12.1e"/>
        <vers num="12.1ec"/>
        <vers num="12.1ex"/>
        <vers num="12.1ez"/>
        <vers num="12.1ga"/>
        <vers num="12.1gb"/>
        <vers num="12.1t"/>
        <vers num="12.1xa"/>
        <vers num="12.1xd"/>
        <vers num="12.1xh"/>
        <vers num="12.1xi"/>
        <vers num="12.1xl"/>
        <vers num="12.1xm"/>
        <vers num="12.1xq"/>
        <vers num="12.1xs"/>
        <vers num="12.1xu"/>
        <vers num="12.1xw"/>
        <vers num="12.1xx"/>
        <vers num="12.1xy"/>
        <vers num="12.1xz"/>
        <vers num="12.1ya"/>
        <vers num="12.1yb"/>
        <vers num="12.1yd"/>
        <vers num="12.2"/>
        <vers num="12.2b"/>
        <vers num="12.2bc"/>
        <vers num="12.2bw"/>
        <vers num="12.2by"/>
        <vers num="12.2cx"/>
        <vers num="12.2dd"/>
        <vers num="12.2dx"/>
        <vers num="12.2mc"/>
        <vers num="12.2s"/>
        <vers num="12.2su"/>
        <vers num="12.2sy"/>
        <vers num="12.2sz"/>
        <vers num="12.2t"/>
        <vers num="12.2xa"/>
        <vers num="12.2xb"/>
        <vers num="12.2xc"/>
        <vers num="12.2xf"/>
        <vers num="12.2xg"/>
        <vers num="12.2xk"/>
        <vers num="12.2xl"/>
        <vers num="12.2xs"/>
        <vers num="12.2xt"/>
        <vers num="12.2xv"/>
        <vers num="12.2yd"/>
        <vers num="12.2ye"/>
        <vers num="12.2yn"/>
        <vers num="12.2yt"/>
        <vers num="12.2yw"/>
        <vers num="12.2yx"/>
        <vers num="12.2yy"/>
        <vers num="12.2yz"/>
        <vers num="12.2za"/>
        <vers num="12.2zb"/>
        <vers num="12.2zd"/>
        <vers num="12.2ze"/>
        <vers num="12.2zj"/>
        <vers num="12.2zn"/>
        <vers num="12.3"/>
        <vers num="12.3b"/>
        <vers num="12.3bc"/>
        <vers num="12.3bw"/>
        <vers num="12.3t"/>
        <vers num="12.3xb"/>
        <vers num="12.3xd"/>
        <vers num="12.3xf"/>
        <vers num="12.3xh"/>
        <vers num="12.3xi"/>
        <vers num="12.3xj"/>
        <vers num="12.3xm"/>
        <vers num="12.3xq"/>
        <vers num="12.3xu"/>
        <vers num="12.3xw"/>
        <vers num="12.3yf"/>
        <vers num="12.3yg"/>
        <vers num="12.3yj"/>
        <vers num="12.3yk"/>
        <vers num="12.3ym"/>
        <vers num="12.3yq"/>
        <vers num="12.3yt"/>
        <vers num="12.3yu"/>
        <vers num="12.3yx"/>
        <vers num="12.4"/>
        <vers num="12.4mr"/>
        <vers num="12.4t"/>
        <vers num="12.4xa"/>
        <vers num="12.4xb"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0341" published="2006-01-06" name="CVE-2006-0341" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in WCONSOLE.DLL in Rockliffe MailSite 5.x and 6.1.22 and earlier allows remote attackers to inject arbitrary web script or HTML via the query string.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18551" source="SECUNIA" patch="1" adv="1">18551</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=113777628702043&amp;w=2" source="FULLDISC" patch="1" adv="1">20060120 RockLiffe MailSite wconsole.dll Denial of Service/Script Injection Vulnerability</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0284" source="VUPEN">ADV-2006-0284</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24256" source="XF">mailsite-wconsole-xss(24256)</ref>
      <ref url="http://www.securityfocus.com/bid/16330" source="BID">16330</ref>
      <ref url="http://www.osvdb.org/22677" source="OSVDB">22677</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rockliffe" name="mailsite">
        <vers prev="1" num="6.1.22"/>
        <vers prev="1" num="7.0.3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0342" published="2006-01-20" name="CVE-2006-0342" modified="2011-10-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">RockLiffe MailSite HTTP Mail management agent (httpma) 7.0.3.1 allows remote attackers to cause a denial of service (CPU consumption and crash) via a malformed query string containing special characters such as "|".</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18551" source="SECUNIA" patch="1" adv="1">18551</ref>
      <ref url="http://marc.theaimsgroup.com/?l=full-disclosure&amp;m=113777628702043&amp;w=2" source="FULLDISC" patch="1" adv="1">20060120 RockLiffe MailSite wconsole.dll Denial of Service/Script Injection Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24255" source="XF">mailsite-wconsole-dos(24255)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0284" source="VUPEN" adv="1">ADV-2006-0284</ref>
      <ref url="http://www.securityfocus.com/bid/16331" source="BID">16331</ref>
      <ref url="http://www.osvdb.org/22678" source="OSVDB">22678</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rockliffe" name="mailsite">
        <vers num="7.0.3.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0343" published="2006-01-20" name="CVE-2006-0343" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Port Discovery Standard and Advanced features in Hitachi JP1/NetInsight II allows attackers to stop the Port Discovery service via unknown vectors involving "invalid format data".</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18538" source="SECUNIA" patch="1" adv="1">18538</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0267" source="VUPEN">ADV-2006-0267</ref>
      <ref url="http://www.securityfocus.com/bid/16327" source="BID">16327</ref>
      <ref url="http://www.osvdb.org/22676" source="OSVDB">22676</ref>
      <ref url="http://www.hitachi-support.com/security_e/vuls_e/HS05-027_e/index-e.html" source="CONFIRM">http://www.hitachi-support.com/security_e/vuls_e/HS05-027_e/index-e.html</ref>
      <ref url="http://securitytracker.com/id?1015520" source="SECTRACK">1015520</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24243" source="XF">hitachi-jp1netinsight-port-dos(24243)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hitachi" name="jpi_netsight_ii_port_discovery_advance">
        <vers num="r_15237_9154_07_50"/>
      </prod>
      <prod vendor="hitachi" name="jpi_netsight_ii_port_discovery_standard">
        <vers num="r_15237_9164_07_00"/>
        <vers num="r_15237_9164_07_01"/>
        <vers num="r_15237_9164_07_02"/>
        <vers num="r_15237_9164_07_03"/>
        <vers num="r_15237_9164_07_04"/>
        <vers num="r_15237_9164_07_05"/>
        <vers num="r_15237_9164_07_06"/>
        <vers num="r_15237_9164_07_07"/>
        <vers num="r_15237_9164_07_08"/>
        <vers num="r_15237_9164_07_09"/>
        <vers num="r_15237_9164_07_10"/>
        <vers num="r_15237_9164_07_11"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0344" published="2006-01-20" name="CVE-2006-0344" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Intervations FileCOPA FTP Server 1.01 allows remote attackers to read and write arbitrary files via a .. (dot dot) in the (1) STOR and (2) RETR commands.</descript>
    </desc>
    <loss_types>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.nii.co.in/vuln/filecopa.html" source="MISC" patch="1" adv="1">http://www.nii.co.in/vuln/filecopa.html</ref>
      <ref url="http://secunia.com/advisories/18550" source="SECUNIA" patch="1" adv="1">18550</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24257" source="XF">filecopa-ftp-directory-traversal(24257)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0285" source="VUPEN">ADV-2006-0285</ref>
      <ref url="http://www.securityfocus.com/bid/16335" source="BID">16335</ref>
      <ref url="http://www.osvdb.org/22694" source="OSVDB">22694</ref>
    </refs>
    <vuln_soft>
      <prod vendor="intervations" name="filecopa">
        <vers num="1.01"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0345" published="2006-01-20" name="CVE-2006-0345" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in SaralBlog 1.0 allow remote attackers to execute arbitrary SQL commands via the search parameter to search.php.  NOTE: the id/viewprofile.php issue is already covered by CVE-2005-4058.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16306" source="BID">16306</ref>
      <ref url="http://evuln.com/vulns/40/summary.html" source="MISC" adv="1">http://evuln.com/vulns/40/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24218" source="XF">saralblog-search-sql-injection(24218)</ref>
      <ref url="http://www.osvdb.org/22740" source="OSVDB">22740</ref>
      <ref url="http://securitytracker.com/id?1015517" source="SECTRACK">1015517</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2006-01/0372.html" source="BUGTRAQ">20060118 [eVuln] SaralBlog XSS &amp; Multiple SQL Injection Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="saral_kaushik" name="saralblog">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0346" published="2006-01-20" name="CVE-2006-0346" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in SaralBlog 1.0 allows remote attackers to inject arbitrary web script or HTML via a website field in a new comment to view.php, which is not properly handled in the comment function in functions.php.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16306" source="BID">16306</ref>
      <ref url="http://evuln.com/vulns/40/summary.html" source="MISC" adv="1">http://evuln.com/vulns/40/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24219" source="XF">saralblog-view-xss(24219)</ref>
      <ref url="http://www.osvdb.org/27907" source="OSVDB">27907</ref>
      <ref url="http://securitytracker.com/id?1015517" source="SECTRACK">1015517</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2006-01/0372.html" source="BUGTRAQ">20060118 [eVuln] SaralBlog XSS &amp; Multiple SQL Injection Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="saral_kaushik" name="saralblog">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0347" published="2006-01-20" name="CVE-2006-0347" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in ELOG before 2.6.1 allows remote attackers to access arbitrary files outside of the elog directory via "../" (dot dot) sequences in the URL.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16315" source="BID" patch="1">16315</ref>
      <ref url="http://secunia.com/advisories/18533" source="SECUNIA" patch="1" adv="1">18533</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24224" source="XF">elog-dotdot-directory-traversal(24224)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0262" source="VUPEN">ADV-2006-0262</ref>
      <ref url="http://midas.psi.ch/elog/download/ChangeLog" source="MISC">http://midas.psi.ch/elog/download/ChangeLog</ref>
      <ref url="http://www.osvdb.org/22647" source="OSVDB">22647</ref>
      <ref url="http://www.debian.org/security/2006/dsa-967" source="DEBIAN">DSA-967</ref>
      <ref url="http://secunia.com/advisories/18783" source="SECUNIA">18783</ref>
    </refs>
    <vuln_soft>
      <prod vendor="stefan_ritt" name="elog_web_logbook">
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.1.0"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.1.3"/>
        <vers num="2.2.0"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.4"/>
        <vers num="2.5"/>
        <vers num="2.5.6"/>
        <vers num="2.5.7"/>
        <vers num="2.6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0348" published="2006-01-20" name="CVE-2006-0348" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Format string vulnerability in the write_logfile function in ELOG before 2.6.1 allows remote attackers to cause a denial of service (server crash) via unknown attack vectors.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16315" source="BID" patch="1">16315</ref>
      <ref url="http://secunia.com/advisories/18533" source="SECUNIA" patch="1" adv="1">18533</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0262" source="VUPEN">ADV-2006-0262</ref>
      <ref url="http://midas.psi.ch/elog/download/ChangeLog" source="MISC">http://midas.psi.ch/elog/download/ChangeLog</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24221" source="XF">elog-elogd-format-string(24221)</ref>
      <ref url="http://www.osvdb.org/22646" source="OSVDB">22646</ref>
      <ref url="http://www.debian.org/security/2006/dsa-967" source="DEBIAN">DSA-967</ref>
      <ref url="http://secunia.com/advisories/18783" source="SECUNIA">18783</ref>
    </refs>
    <vuln_soft>
      <prod vendor="stefan_ritt" name="elog_web_logbook">
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.1.0"/>
        <vers num="2.1.1"/>
        <vers num="2.1.2"/>
        <vers num="2.1.3"/>
        <vers num="2.2.0"/>
        <vers num="2.2.1"/>
        <vers num="2.2.2"/>
        <vers num="2.2.3"/>
        <vers num="2.2.4"/>
        <vers num="2.4"/>
        <vers num="2.5"/>
        <vers num="2.5.6"/>
        <vers num="2.5.7"/>
        <vers num="2.6.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0349" published="2006-01-20" name="CVE-2006-0349" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in eggblog 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to blog.php.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16305" source="BID">16305</ref>
      <ref url="http://securitytracker.com/id?1015505" source="SECTRACK" adv="1">1015505</ref>
      <ref url="http://secunia.com/advisories/18212" source="SECUNIA" adv="1">18212</ref>
      <ref url="http://evuln.com/vulns/39/summary.html" source="MISC" adv="1">http://evuln.com/vulns/39/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24210" source="XF">eggblog-blog-sql-injection(24210)</ref>
      <ref url="http://www.osvdb.org/22751" source="OSVDB">22751</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2006-01/0371.html" source="BUGTRAQ">20060118 [eVuln] eggblog Multiple SQL Injection &amp; XSS Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="epic_designs" name="eggblog">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0350" published="2006-01-20" name="CVE-2006-0350" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in eggblog 2.0 allow remote attackers to inject arbitrary web script or HTML via the message field to topic.php.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16305" source="BID">16305</ref>
      <ref url="http://securitytracker.com/id?1015505" source="SECTRACK" adv="1">1015505</ref>
      <ref url="http://secunia.com/advisories/18212" source="SECUNIA" adv="1">18212</ref>
      <ref url="http://evuln.com/vulns/39/summary.html" source="MISC" adv="1">http://evuln.com/vulns/39/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24209" source="XF">eggblog-topic-xss(24209)</ref>
      <ref url="http://www.osvdb.org/22752" source="OSVDB">22752</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2006-01/0371.html" source="BUGTRAQ">20060118 [eVuln] eggblog Multiple SQL Injection &amp; XSS Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="epic_designs" name="eggblog">
        <vers num="2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0351" published="2006-01-20" name="CVE-2006-0351" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified "critical denial-of-service vulnerability" in MyDNS before 1.1.0 has unknown impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.osvdb.org/22636" source="OSVDB" patch="1">22636</ref>
      <ref url="http://secunia.com/advisories/18532" source="SECUNIA" patch="1" adv="1">18532</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0256" source="VUPEN">ADV-2006-0256</ref>
      <ref url="http://mydns.bboy.net/download/changelog.html" source="CONFIRM">http://mydns.bboy.net/download/changelog.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24228" source="XF">mydns-query-dos(24228)</ref>
      <ref url="http://www.securityfocus.com/bid/16431" source="BID">16431</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200601-16.xml" source="GENTOO">GLSA-200601-16</ref>
      <ref url="http://www.debian.org/security/2006/dsa-963" source="DEBIAN">DSA-963</ref>
      <ref url="http://securitytracker.com/id?1015521" source="SECTRACK">1015521</ref>
      <ref url="http://secunia.com/advisories/18653" source="SECUNIA">18653</ref>
      <ref url="http://secunia.com/advisories/18641" source="SECUNIA">18641</ref>
    </refs>
    <vuln_soft>
      <prod vendor="don_moore" name="mydns">
        <vers num="0.10.0"/>
        <vers num="0.10.1"/>
        <vers num="0.10.2"/>
        <vers num="0.10.3"/>
        <vers num="0.10.4"/>
        <vers num="0.11.0"/>
        <vers num="0.6"/>
        <vers num="0.7"/>
        <vers num="0.7.1"/>
        <vers num="0.8"/>
        <vers num="0.8.1"/>
        <vers num="0.8.2"/>
        <vers num="0.8.3"/>
        <vers num="0.9.0"/>
        <vers num="0.9.1"/>
        <vers num="0.9.10"/>
        <vers num="0.9.12"/>
        <vers num="0.9.13"/>
        <vers num="0.9.2"/>
        <vers num="0.9.3"/>
        <vers num="0.9.5"/>
        <vers num="0.9.6"/>
        <vers num="0.9.7"/>
        <vers num="0.9.8"/>
        <vers num="0.9.9"/>
        <vers num="1.0.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0352" published="2006-01-20" name="CVE-2006-0352" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The default configuration of Fluffington FLog 1.01 installs users.0.dat under the web document root with insufficient access control, which might allow remote attackers to obtain sensitive information (login credentials) via a direct request.  NOTE: It was later reported that 1.1.2 is also affected.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/456069/100/0/threaded" source="BUGTRAQ">20070105 Flog 1.1.2 Remote Admin Password Disclosure</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422268/100/0/threaded" source="BUGTRAQ">20060117 [eVuln] Flog Information Disclosure Vulnerability</ref>
      <ref url="http://evuln.com/vulns/38/summary/bt/" source="MISC">http://evuln.com/vulns/38/summary/bt/</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/31307" source="XF">flog-admin-info-disclosure(31307)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24193" source="XF">flog-data-directory-insecure(24193)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fluffington" name="flog">
        <vers num="1.01"/>
        <vers num="1.1.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0353" published="2006-01-22" name="CVE-2006-0353" modified="2011-05-19" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:P)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">unix_random.c in lshd for lsh 2.0.1 leaks file descriptors related to the randomness generator, which allows local users to cause a denial of service by truncating the seed file, which prevents the server from starting, or obtain sensitive seed information that could be used to crack keys.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16357" source="BID" patch="1">16357</ref>
      <ref url="http://www.debian.org/security/2006/dsa-956" source="DEBIAN" patch="1" adv="1">DSA-956</ref>
      <ref url="http://secunia.com/advisories/18623" source="SECUNIA" patch="1" adv="1">18623</ref>
      <ref url="http://secunia.com/advisories/18564" source="SECUNIA" patch="1" adv="1">18564</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24263" source="XF">lsh-file-descriptor-leak(24263)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0301" source="VUPEN" adv="1">ADV-2006-0301</ref>
      <ref url="http://www.osvdb.org/22695" source="OSVDB">22695</ref>
      <ref url="http://lists.lysator.liu.se/pipermail/lsh-bugs/2006q1/000467.html" source="MLIST" adv="1">[lsh-bugs] SECURITY: lshd leaks fd:s to user shells</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="lsh">
        <vers num="2.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0354" published="2006-01-22" name="CVE-2006-0354" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:A/AC:L/Au:S/C:N/I:N/A:C)" CVSS_score="5.5" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="5.1" CVSS_base_score="5.5">
    <desc>
      <descript source="cve">Cisco IOS before 12.3-7-JA2 on Aironet Wireless Access Points (WAP) allows remote authenticated users to cause a denial of service (termination of packet passing or termination of client connections) by sending the management interface a large number of spoofed ARP packets, which creates a large ARP table that exhausts memory, aka Bug ID CSCsc16644.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <local_network/>
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1015483" source="SECTRACK" patch="1">1015483</ref>
      <ref url="http://secunia.com/advisories/18430" source="SECUNIA" patch="1" adv="1">18430</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24086" source="XF">cisco-aironet-arp-dos(24086)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0176" source="VUPEN">ADV-2006-0176</ref>
      <ref url="http://www.securityfocus.com/bid/16217" source="BID">16217</ref>
      <ref url="http://www.osvdb.org/22375" source="OSVDB">22375</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20060112-wireless.shtml" source="CISCO" adv="1">20060112 Access Point Memory Exhaustion from ARP Attacks</ref>
      <ref url="http://securityreason.com/securityalert/339" source="SREASON">339</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5680" source="OVAL">oval:org.mitre.oval:def:5680</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="aironet_ap1100">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="aironet_ap1130ag">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="aironet_ap1200">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="aironet_ap1230ag">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="aironet_ap1240ag">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="aironet_ap1300">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="aironet_ap1400">
        <vers num=""/>
      </prod>
      <prod vendor="cisco" name="aironet_ap350">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0355" published="2006-01-22" name="CVE-2006-0355" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Helmsman Research (aka CoolUtils) HomeFtp 1.1 allows remote attackers to cause an unspecified denial of service via a long USER command combined with a long PASS command and an NLST command.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421869/100/0/threaded" source="BUGTRAQ" adv="1">20060114 [KAPDA::#21] - HomeFtp v1.1 Denial of Service</ref>
      <ref url="http://www.kapda.ir/advisory-202.html" source="MISC" adv="1">http://www.kapda.ir/advisory-202.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24152" source="XF">homeftp-long-command-dos(24152)</ref>
      <ref url="http://www.securityfocus.com/bid/16238" source="BID">16238</ref>
      <ref url="http://securityreason.com/securityalert/350" source="SREASON">350</ref>
    </refs>
    <vuln_soft>
      <prod vendor="helmsman_research" name="homeftp">
        <vers num="1.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0356" published="2006-01-22" name="CVE-2006-0356" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Ari Pikivirta Home Ftp Server 1.0.7 allows remote attackers to cause an unspecified denial of service via a long USER command combined with a long PASS command.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422033/100/0/threaded" source="BUGTRAQ" adv="1">20060115 Homeftp r1.0.7 Denial of Service</ref>
      <ref url="http://www.kapda.ir/advisory-211.html" source="MISC" adv="1">http://www.kapda.ir/advisory-211.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24227" source="XF">homeftpserver-long-command-dos(24227)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ari_pikivirta" name="home_ftp_server">
        <vers num="1.0.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0357" published="2006-01-22" name="CVE-2006-0357" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Grant Averett Cerberus FTP Server 2.32, and possibly earlier versions, allows remote attackers to cause an unspecified denial of service via a long string that does not contain a valid FTP command.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422162/100/0/threaded" source="BUGTRAQ" adv="1">20060115 Cerberus FTP Server 2.32 Denial of Service</ref>
      <ref url="http://www.kapda.ir/advisory-210.html" source="MISC" adv="1">http://www.kapda.ir/advisory-210.html</ref>
      <ref url="http://www.cerberusftp.com/cerberus-releasenotes.htm" source="MISC">http://www.cerberusftp.com/cerberus-releasenotes.htm</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24226" source="XF">cerberus-long-command-dos(24226)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="grant_averett" name="cerberus_ftp_server">
        <vers num="2.32"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0358" published="2006-01-22" name="CVE-2006-0358" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in PowerPortal, possibly 1.1 beta through 1.3, allow remote attackers to execute arbitrary SQL commands via the search parameter in (1) index.php and (2) search.php. NOTE: This issue might overlap CVE-2004-0663.2.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16279" source="BID">16279</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422151/100/0/threaded" source="BUGTRAQ">20060117 PowerPortal Cross-Site Scripting Vulnerability</ref>
      <ref url="http://web.archive.org/web/20050303003128/http://powerportal.sourceforge.net/" source="MISC">http://web.archive.org/web/20050303003128/http://powerportal.sourceforge.net/</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24196" source="XF">powerportal-search-index-xss(24196)</ref>
      <ref url="http://www.osvdb.org/27958" source="OSVDB">27958</ref>
      <ref url="http://www.osvdb.org/27957" source="OSVDB">27957</ref>
      <ref url="http://secunia.com/advisories/10172" source="SECUNIA">10172</ref>
    </refs>
    <vuln_soft>
      <prod vendor="powerportal" name="powerportal">
        <vers num="1.1b"/>
        <vers num="1.3"/>
        <vers num="1.3b"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0359" published="2006-01-22" name="CVE-2006-0359" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in CounterPath eyeBeam SIP Softphone allows remote attackers to (1) cause a denial of service (device crash) via SIP INVITE commands with a long header field name sent during startup and (2) cause a denial of service (device hang or crash) via SIP INVITE commands with a long header field name sent during a call.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24181" source="XF">eyebeam-sip-header-bo(24181)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0259" source="VUPEN">ADV-2006-0259</ref>
      <ref url="http://www.securityfocus.com/bid/16253" source="BID">16253</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/446573/100/0/threaded" source="BUGTRAQ">20060921 Re: CounterPath eyeBeam Handing SIP header Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422009/100/0/threaded" source="BUGTRAQ">20060116 CounterPath eyeBeam Handing SIP header Vulnerabilities</ref>
      <ref url="http://securityreason.com/securityalert/354" source="SREASON">354</ref>
      <ref url="http://secunia.com/advisories/18516" source="SECUNIA" adv="1">18516</ref>
      <ref url="http://blog.donews.com/zwell/archive/2006/01/17/698810.aspx" source="MISC">http://blog.donews.com/zwell/archive/2006/01/17/698810.aspx</ref>
    </refs>
    <vuln_soft>
      <prod vendor="counterpath" name="eyebeam_sip_softphone">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0360" published="2006-01-22" name="CVE-2006-0360" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">MPM SIP HP-180W Wireless IP Phone WE.00.17 allows remote attackers to obtain sensitive information and possibly cause a denial of service via a direct connection to UDP port 9090, which is undocumented and does not require authentication.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <vuln_types>
      <access/>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16285" source="BID">16285</ref>
      <ref url="http://secunia.com/advisories/18512" source="SECUNIA" adv="1">18512</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041437.html" source="FULLDISC" adv="1">20060116 MPM HP-180W VoIP wireless desktop phone undocumented port UDP/9090</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24147" source="XF">mpn-hp180w-default-port(24147)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mpm" name="hp-180w_voip_wifi_phone">
        <vers num="we.00.17"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0361" published="2006-01-22" name="CVE-2006-0361" modified="2011-03-07" discovered="2006-01-15" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in addcomment.php in Bit 5 Blog 8.01 allows remote attackers to inject arbitrary web script or HTML via a javascript URI in an &lt;a> tag in the comment parameter, which strips most tags but not &lt;a>.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0195" source="VUPEN">ADV-2006-0195</ref>
      <ref url="http://www.securityfocus.com/bid/16246" source="BID">16246</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421994/100/0/threaded" source="BUGTRAQ" adv="1">20060115 [eVuln] Bit 5 Blog JavaScript Insertion Vulnerability</ref>
      <ref url="http://www.osvdb.org/22446" source="OSVDB">22446</ref>
      <ref url="http://secunia.com/advisories/18464" source="SECUNIA" adv="1">18464</ref>
      <ref url="http://evuln.com/vulns/32/summary/" source="MISC" adv="1">http://evuln.com/vulns/32/summary/</ref>
      <ref url="http://evuln.com/vulns/32/exploit" source="MISC">http://evuln.com/vulns/32/exploit</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24129" source="XF">bit5blog-addcomment-xss(24129)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bit_5_blog" name="bit_5_blog">
        <vers num="8.01"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0362" published="2006-01-22" name="CVE-2006-0362" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">TippingPoint Intrusion Prevention System (IPS) TOS before 2.1.4.6324, and TOS 2.2.x before 2.2.1.6506, allow remote attackers to cause a denial of service (CPU consumption) via an unknown vector, probably involving an HTTP request with a negative number in the Content-Length header.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.osvdb.org/22504" source="OSVDB" patch="1">22504</ref>
      <ref url="http://www.eweek.com/article2/0,1759,1912048,00.asp" source="CONFIRM" patch="1">http://www.eweek.com/article2/0,1759,1912048,00.asp</ref>
      <ref url="http://isc.sans.org/diary.php?storyid=1042" source="MISC" patch="1">http://isc.sans.org/diary.php?storyid=1042</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24200" source="XF">tippingpoint-ips-http-traffic-dos(24200)</ref>
      <ref url="http://www.securityfocus.com/bid/16299" source="BID">16299</ref>
      <ref url="http://securitytracker.com/id?1015511" source="SECTRACK">1015511</ref>
      <ref url="http://secunia.com/advisories/18515" source="SECUNIA">18515</ref>
    </refs>
    <vuln_soft>
      <prod vendor="3com" name="tippingpoint_ips_tos">
        <vers num="2.1.3.6323"/>
        <vers num="2.2.0.6504"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0363" published="2006-01-22" name="CVE-2006-0363" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The "Remember my Password" feature in MSN Messenger 7.5 stores passwords in an encrypted format under the HKEY_CURRENT_USER\Software\Microsoft\IdentityCRL\Creds registry key, which might allow local users to obtain the original passwords via a program that calls CryptUnprotectData, as demonstrated by the "MSN Password Recovery.exe" program.  NOTE: it could be argued that local-only password recovery is inherently insecure because the decryption methods and keys must be stored somewhere on the local system, and are thus inherently accessible with varying degrees of effort.  Perhaps this issue should not be included in CVE.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422283/100/0/threaded" source="BUGTRAQ">20060117 Re: MSN Messenger Password Decrypter for WinXP/2003</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421921/100/0/threaded" source="BUGTRAQ">20060113 Re: MSN Messenger Password Decrypter for WinXP/2003</ref>
      <ref url="http://www.msn-password-recovery.com/" source="MISC">http://www.msn-password-recovery.com/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="msn_messenger">
        <vers num="7.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0364" published="2006-01-22" name="CVE-2006-0364" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in MyBulletinBoard (MyBB) allows remote attackers to inject arbitrary web script or HTML via a signature containing a JavaScript URI in the SRC attribute of an IMG element, in which the URI uses SGML numeric character references without trailing semicolons, as demonstrated by "&amp;#106&amp;#97&amp;#118&amp;#97&amp;#115&amp;#99&amp;#114&amp;#105&amp;#112&amp;#116".</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18544" source="SECUNIA" patch="1" adv="1">18544</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24225" source="XF">mybb-html-signature-xss(24225)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0255" source="VUPEN">ADV-2006-0255</ref>
      <ref url="http://www.securityfocus.com/bid/16308" source="BID">16308</ref>
      <ref url="http://www.osvdb.org/22628" source="OSVDB">22628</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2006-01/0332.html" source="BUGTRAQ">20060118 MyBB Signature HTML Code Injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mybulletinboard" name="mybulletinboard">
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0_final"/>
        <vers num="1.0_pr2"/>
        <vers num="1.0_preview_release_2"/>
        <vers num="1.0_rc2"/>
        <vers num="1.0_rc4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0365" published="2006-01-22" name="CVE-2006-0365" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in XMB (aka extreme message board) allows remote attackers to inject arbitrary web script or HTML via JavaScript in the SRC attribute of an IMG element.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422277/100/0/threaded" source="BUGTRAQ">20060118 XMB Forum HTML Code Injection</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24208" source="XF">xmbforum-imgsrc-xss(24208)</ref>
      <ref url="http://www.osvdb.org/27920" source="OSVDB">27920</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xmb_software" name="xmb_forum">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0366" published="2006-01-22" name="CVE-2006-0366" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Phpclanwebsite (aka PCW) allows remote attackers to inject arbitrary web script or HTML via a javascript URI in a BBCode img tag.</descript>
    </desc>
    <sols>
      <sol source="nvd">A simple fix has been released on the Main PCW site available directly at &lt;a href="http://www.phpclanwebsite.com/index.php?page=downloads&amp;func=browselist&amp;par=1">http://www.phpclanwebsite.com/index.php?page=downloads&amp;func=browselist&amp;par=1
&lt;/a>Please download and install imediately. </sol>
    </sols>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16300" source="BID" patch="1">16300</ref>
      <ref url="http://secunia.com/advisories/18541" source="SECUNIA" patch="1" adv="1">18541</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0254" source="VUPEN">ADV-2006-0254</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422265/100/0/threaded" source="BUGTRAQ">20060117 Phpclanwebsite BBCode IMG Tag XSS Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpclanwebsite" name="phpclanwebsite">
        <vers num="1.23.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0367" published="2006-01-22" name="CVE-2006-0367" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in Cisco CallManager 3.2 and earlier, 3.3 before 3.3(5)SR1, 4.0 before 4.0(2a)SR2c, and 4.1 before 4.1(3)SR2 allows remote authenticated users with read-only administrative privileges to obtain full administrative privileges via a "crafted URL on the CCMAdmin web page."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.osvdb.org/22621" source="OSVDB" patch="1">22621</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20060118-ccmpe.shtml" source="CISCO" patch="1" adv="1">20060118 Cisco Call Manager Privilege Escalation</ref>
      <ref url="http://securitytracker.com/id?1015502" source="SECTRACK" patch="1">1015502</ref>
      <ref url="http://secunia.com/advisories/18501" source="SECUNIA" patch="1" adv="1">18501</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24172" source="XF">cisco-callmanager-ccmadmin-gain-priv(24172)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0250" source="VUPEN" adv="1">ADV-2006-0250</ref>
      <ref url="http://www.securityfocus.com/bid/16293" source="BID">16293</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="call_manager">
        <vers num="1.0"/>
        <vers num="2.0"/>
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="3.1(2)"/>
        <vers num="3.1(3a)"/>
        <vers num="3.2"/>
        <vers num="3.3"/>
        <vers num="3.3(3)"/>
        <vers num="3.3(3)es61"/>
        <vers num="3.3(4)es25"/>
        <vers num="3.3(5)"/>
        <vers num="4.0"/>
        <vers num="4.0(2a)es40"/>
        <vers num="4.0(2a)sr2b"/>
        <vers num="4.1(2)es33"/>
        <vers num="4.1(3)es07"/>
        <vers num="4.1(3)sr1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0368" published="2006-01-22" name="CVE-2006-0368" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Cisco CallManager 3.2 and earlier, 3.3 before 3.3(5)SR1, 4.0 before 4.0(2a)SR2c, and 4.1 before 4.1(3)SR2 allow remote attackers to (1) cause a denial of service (CPU and memory consumption) via a large number of open TCP connections to port 2000 and (2) cause a denial of service (fill the Windows Service Manager communication queue) via a large number of TCP connections to port 2001, 2002, or 7727.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18494" source="SECUNIA" patch="1" adv="1">18494</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0249" source="VUPEN">ADV-2006-0249</ref>
      <ref url="http://www.securityfocus.com/bid/16295" source="BID">16295</ref>
      <ref url="http://www.cisco.com/warp/public/707/cisco-sa-20060118-ccmdos.shtml" source="CISCO">20060118 Cisco Call Manager Denial of Service</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24180" source="XF">cisco-callmanager-port-connection-dos(24180)</ref>
      <ref url="http://www.osvdb.org/22623" source="OSVDB">22623</ref>
      <ref url="http://www.osvdb.org/22622" source="OSVDB">22622</ref>
      <ref url="http://securitytracker.com/id?1015503" source="SECTRACK">1015503</ref>
      <ref url="http://securityreason.com/securityalert/359" source="SREASON">359</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="call_manager">
        <vers num="1.0"/>
        <vers num="2.0"/>
        <vers num="3.0"/>
        <vers num="3.1"/>
        <vers num="3.1(2)"/>
        <vers num="3.1(3a)"/>
        <vers num="3.2"/>
        <vers num="3.3"/>
        <vers num="3.3(3)"/>
        <vers num="3.3(3)es61"/>
        <vers num="3.3(4)es25"/>
        <vers num="3.3(5)"/>
        <vers num="3.3(5)es30"/>
        <vers num="4.0"/>
        <vers num="4.0(2a)es40"/>
        <vers num="4.0(2a)es62"/>
        <vers num="4.0(2a)sr2b"/>
        <vers num="4.1(2)es33"/>
        <vers num="4.1(2)es55"/>
        <vers num="4.1(3)es07"/>
        <vers num="4.1(3)es32"/>
        <vers num="4.1(3)sr1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0369" published="2006-01-22" name="CVE-2006-0369" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">** DISPUTED **  MySQL 5.0.18 allows local users with access to a VIEW to obtain sensitive information via the "SELECT * FROM information_schema.views;" query, which returns the query that created the VIEW.  NOTE: this issue has been disputed by third parties, saying that the availability of the schema is a normal and sometimes desired aspect of database access.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423432/100/0/threaded" source="BUGTRAQ">20060128 Re: MySQL 5.0 information leak?</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423228/100/0/threaded" source="BUGTRAQ">20060123 RE: MySQL 5.0 information leak?</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423204/100/0/threaded" source="BUGTRAQ">20060124 Re: MySQL 5.0 information leak?</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423180/30/7310/threaded" source="BUGTRAQ">20060122 Re: MySQL 5.0 information leak?</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422491/100/0/threaded" source="BUGTRAQ" adv="1">20060120 MySQL 5.0 information leak?</ref>
      <ref url="http://www.securityfocus.com/archive/1/422698/100/0/threaded" source="BUGTRAQ">20060121 Re: MySQL 5.0 information leak?</ref>
      <ref url="http://www.securityfocus.com/archive/1/422592/100/0/threaded" source="BUGTRAQ">20060121 RE: MySQL 5.0 information leak?</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers num="5.0.18"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0370" published="2006-01-22" name="CVE-2006-0370" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Noah Medling RCBlog 1.03 stores the data and config directories under the web root with insufficient access control, which allows remote attackers to view account names and MD5 password hashes.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <access/>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422499/100/0/threaded" source="BUGTRAQ" adv="1">20060120 [eVuln] RCBlog Directory Traversal &amp; Sensitive Information Disclosure</ref>
      <ref url="http://www.fluffington.com/index.php?page=rcblog" source="MISC">http://www.fluffington.com/index.php?page=rcblog</ref>
      <ref url="http://secunia.com/advisories/18547" source="SECUNIA" adv="1">18547</ref>
      <ref url="http://evuln.com/vulns/42/summary.html" source="MISC" adv="1">http://evuln.com/vulns/42/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24249" source="XF">rcblog-data-config-insecure-directories(24249)</ref>
      <ref url="http://www.osvdb.org/22679" source="OSVDB">22679</ref>
      <ref url="http://securitytracker.com/id?1015523" source="SECTRACK">1015523</ref>
    </refs>
    <vuln_soft>
      <prod vendor="noah_medling" name="rcblog">
        <vers num="1.03"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0371" published="2006-01-22" name="CVE-2006-0371" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in index.php in Noah Medling RCBlog 1.03 allows remote attackers to read arbitrary .txt files, possibly including one that stores the administrator's account name and password, via a .. (dot dot) in the post parameter.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16342" source="BID">16342</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422499/100/0/threaded" source="BUGTRAQ" adv="1">20060120 [eVuln] RCBlog Directory Traversal &amp; Sensitive Information Disclosure</ref>
      <ref url="http://www.fluffington.com/index.php?page=rcblog" source="MISC">http://www.fluffington.com/index.php?page=rcblog</ref>
      <ref url="http://secunia.com/advisories/18547" source="SECUNIA" adv="1">18547</ref>
      <ref url="http://evuln.com/vulns/42/summary.html" source="MISC" adv="1">http://evuln.com/vulns/42/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/27042" source="XF">rcblog-index-file-include(27042)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24248" source="XF">rcblog-index-directory-traversal(24248)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/436784/30/4500/threaded" source="BUGTRAQ">20060611 RCblog 1.03 Directory Traversal [index.php]</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425392/100/0/threaded" source="BUGTRAQ">20060218 RCblog exploit [fun]</ref>
      <ref url="http://www.osvdb.org/22680" source="OSVDB">22680</ref>
      <ref url="http://securitytracker.com/id?1015523" source="SECTRACK">1015523</ref>
    </refs>
    <vuln_soft>
      <prod vendor="noah_medling" name="rcblog">
        <vers num="1.03"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0372" published="2006-01-22" name="CVE-2006-0372" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in config.php in Insane Visions BlogPHP, possibly 1.0, allow remote attackers to execute arbitrary SQL commands via the (1) blogphp_username or (2) blogphp_password parameter in a cookie.</descript>
    </desc>
    <sols>
      <sol source="nvd">BlogPHP version 2.0 was released to fix the config.php exploit and is available for download at &lt;a href="http://sourceforge.net/project/showfiles.php?group_id=156043">http://sourceforge.net/project/showfiles.php?group_id=156043&lt;/a>.</sol>
    </sols>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16340" source="BID">16340</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422593/100/0/threaded" source="BUGTRAQ">20060121 BlogPHP config.php SQL injection login bypassed</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422484/100/0/threaded" source="BUGTRAQ" adv="1">20060120 BlogPHP config.php SQL injection login bypass</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422483/100/0/threaded" source="BUGTRAQ" adv="1">20060120 BlogPHP config.php SQL injection login bypass</ref>
      <ref url="http://www.osvdb.org/22738" source="OSVDB">22738</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24131" source="XF">blogphp-index-bypass-security(24131)</ref>
      <ref url="http://securityreason.com/securityalert/365" source="SREASON">365</ref>
    </refs>
    <vuln_soft>
      <prod vendor="insane_visions" name="blogphp">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0373" published="2006-01-22" name="CVE-2006-0373" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in register.aspx in Douran FollowWeb allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16302" source="BID">16302</ref>
      <ref url="http://www.osvdb.org/27918" source="OSVDB">27918</ref>
    </refs>
    <vuln_soft>
      <prod vendor="douran" name="followweb">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0374" published="2006-01-22" name="CVE-2006-0374" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Advantage Century Telecommunication (ACT) P202S IP Phone 1.01.21 running firmware 1.1.21 has multiple undocumented ports available, which (1) might allow remote attackers to obtain sensitive information, such as memory contents and internal operating-system data, by directly accessing the VxWorks WDB remote debugging ONCRPC (aka wdbrpc) on UDP 17185, (2) reflect network data using echo (TCP 7), or (3) gain access without authentication using rlogin (TCP 513).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24149" source="XF">act-p202s-default-port(24149)</ref>
      <ref url="http://www.securityfocus.com/bid/16288" source="BID">16288</ref>
      <ref url="http://secunia.com/advisories/18514" source="SECUNIA" adv="1">18514</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041434.html" source="FULLDISC" adv="1">20060116 ACT P202S VoIP wireless phone multiple undocumented ports/services</ref>
    </refs>
    <vuln_soft>
      <prod vendor="advantage_century_telecommunication" name="p202s">
        <vers num="1.01.21_firmware_1.1.21"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0375" published="2006-01-22" name="CVE-2006-0375" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Advantage Century Telecommunication (ACT) P202S IP Phone 1.01.21 running firmware 1.1.21 on VxWorks uses a hardcoded Network Time Protocol (NTP) server in Taiwan, which could allow remote attackers to provide false time information, block access to time information, or conduct other attacks.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18514" source="SECUNIA" adv="1">18514</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041434.html" source="FULLDISC" adv="1">20060116 ACT P202S VoIP wireless phone multiple undocumented ports/services</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24149" source="XF">act-p202s-default-port(24149)</ref>
      <ref url="http://www.securityfocus.com/bid/16288" source="BID">16288</ref>
    </refs>
    <vuln_soft>
      <prod vendor="advantage_century_telecommunication" name="p202s">
        <vers num="1.01.21_firmware_1.1.21"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0376" published="2006-01-22" name="CVE-2006-0376" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The 802.11 wireless client in certain operating systems including Windows 2000, Windows XP, and Windows Server 2003 does not warn the user when (1) it establishes an association with a station in ad hoc (aka peer-to-peer) mode or (2) a station in ad hoc mode establishes an association with it, which allows remote attackers to put unexpected wireless communication into place.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.theta44.org/karma/" source="MISC">http://www.theta44.org/karma/</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/421868/100/0/threaded" source="BUGTRAQ">20060114 [NMRC Advisory] Microsoft Windows Wireless Exposure on Laptops</ref>
      <ref url="http://www.securiteam.com/windowsntfocus/5YP0D2KHHO.html" source="MISC">http://www.securiteam.com/windowsntfocus/5YP0D2KHHO.html</ref>
      <ref url="http://www.nmrc.org/pub/advise/20060114.txt" source="MISC" adv="1">http://www.nmrc.org/pub/advise/20060114.txt</ref>
      <ref url="http://securitytracker.com/id?1015489" source="SECTRACK">1015489</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24157" source="XF">windows-wireless-adhoc-unauth-access(24157)</ref>
      <ref url="http://securityreason.com/securityalert/349" source="SREASON">349</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp2"/>
        <vers num="" edition="sp3"/>
        <vers num="" edition="sp4"/>
        <vers num="" edition="sp4:"/>
        <vers num="" edition="sp4::fr"/>
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="r2"/>
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="gold"/>
        <vers num="" edition="gold:home"/>
        <vers num="" edition="gold:professional"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0377" published="2006-02-23" name="CVE-2006-0377" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">CRLF injection vulnerability in SquirrelMail 1.4.0 to 1.4.5 allows remote attackers to inject arbitrary IMAP commands via newline characters in the mailbox parameter of the sqimap_mailbox_select command, aka "IMAP injection."</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.squirrelmail.org/security/issue/2006-02-15" source="CONFIRM" patch="1">http://www.squirrelmail.org/security/issue/2006-02-15</ref>
      <ref url="http://securitytracker.com/id?1015662" source="SECTRACK" patch="1">1015662</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24849" source="XF">squirrelmail-mailbox-imap-injection(24849)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0689" source="VUPEN">ADV-2006-0689</ref>
      <ref url="http://www.securityfocus.com/bid/16756" source="BID">16756</ref>
      <ref url="http://secunia.com/advisories/18985" source="SECUNIA" adv="1">18985</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11470" source="OVAL">oval:org.mitre.oval:def:11470</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0283.html" source="REDHAT">RHSA-2006:0283</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-March/msg00004.html" source="FEDORA">FEDORA-2006-133</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_05_sr.html" source="SUSE">SUSE-SR:2006:005</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:049" source="MANDRIVA">MDKSA-2006:049</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200603-09.xml" source="GENTOO">GLSA-200603-09</ref>
      <ref url="http://www.debian.org/security/2006/dsa-988" source="DEBIAN">DSA-988</ref>
      <ref url="http://secunia.com/advisories/20210" source="SECUNIA">20210</ref>
      <ref url="http://secunia.com/advisories/19960" source="SECUNIA">19960</ref>
      <ref url="http://secunia.com/advisories/19205" source="SECUNIA">19205</ref>
      <ref url="http://secunia.com/advisories/19176" source="SECUNIA">19176</ref>
      <ref url="http://secunia.com/advisories/19131" source="SECUNIA">19131</ref>
      <ref url="http://secunia.com/advisories/19130" source="SECUNIA">19130</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc" source="SGI">20060501-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squirrelmail" name="squirrelmail">
        <vers num="1.4"/>
        <vers num="1.4.1"/>
        <vers num="1.4.2"/>
        <vers num="1.4.3"/>
        <vers num="1.4.3_r3"/>
        <vers num="1.4.3_rc1"/>
        <vers num="1.4.3a"/>
        <vers num="1.4.4"/>
        <vers num="1.4.4_rc1"/>
        <vers num="1.4.5"/>
        <vers num="1.4.6_rc1"/>
        <vers num="1.4_rc1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0378" published="2006-01-23" name="CVE-2006-0378" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Netrix X-Site Manager allows remote attackers to inject arbitrary web script or HTML via the product_id parameter, as originally demonstrated for a custom mp3players_details.php program.  NOTE: the name of the affected program might be installation-dependent, but it has been identified as "product_details.php" by some sources.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0253" source="VUPEN">ADV-2006-0253</ref>
      <ref url="http://www.securityfocus.com/bid/16313" source="BID">16313</ref>
      <ref url="http://www.osvdb.org/22634" source="OSVDB">22634</ref>
      <ref url="http://secunia.com/advisories/18537" source="SECUNIA" adv="1">18537</ref>
      <ref url="http://osvdb.org/ref/22/22634-x-site.txt" source="MISC">http://osvdb.org/ref/22/22634-x-site.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24234" source="XF">xsitemanager-productdetails-xss(24234)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netrix" name="x-site_manager">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0379" published="2006-01-25" name="CVE-2006-0379" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">FreeBSD kernel 5.4-STABLE and 6.0 does not completely initialize a buffer before making it available to userland, which could allow local users to read portions of kernel memory.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18599" source="SECUNIA" patch="1" adv="1">18599</ref>
      <ref url="http://www.securityfocus.com/bid/16373" source="BID">16373</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:06.kmem.asc" source="FREEBSD">FreeBSD-SA-06:06</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24338" source="XF">bsd-buffer-initialization-disclosure(24338)</ref>
      <ref url="http://www.osvdb.org/22730" source="OSVDB">22730</ref>
      <ref url="http://securitytracker.com/id?1015541" source="SECTRACK">1015541</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="5.4" edition="stable"/>
        <vers num="6.0" edition="stable"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0380" published="2006-01-25" name="CVE-2006-0380" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">A logic error in FreeBSD kernel 5.4-STABLE and 6.0 causes the kernel to calculate an incorrect buffer length, which causes more data to be copied to userland than intended, which could allow local users to read portions of kernel memory.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18599" source="SECUNIA" patch="1" adv="1">18599</ref>
      <ref url="http://www.securityfocus.com/bid/16373" source="BID">16373</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:06.kmem.asc" source="FREEBSD">FreeBSD-SA-06:06</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24340" source="XF">bsd-buffer-length-disclosure(24340)</ref>
      <ref url="http://www.osvdb.org/22731" source="OSVDB">22731</ref>
      <ref url="http://securitytracker.com/id?1015541" source="SECTRACK">1015541</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="5.4" edition="stable"/>
        <vers num="6.0" edition="stable"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0381" published="2006-01-25" name="CVE-2006-0381" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">A logic error in the IP fragment cache functionality in pf in FreeBSD 5.3, 5.4, and 6.0, and OpenBSD, when a 'scrub fragment crop' or 'scrub fragment drop-ovl' rule is being used, allows remote attackers to cause a denial of service (crash) via crafted packets that cause a packet fragment to be inserted twice.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18609" source="SECUNIA" patch="1" adv="1">18609</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:07.pf.asc" source="FREEBSD" patch="1">FreeBSD-SA-06:07</ref>
      <ref url="http://www.securityfocus.com/bid/16375" source="BID">16375</ref>
      <ref url="http://www.openbsd.org/cgi-bin/cvsweb/src/sys/net/pf_norm.c.diff?r1=1.103&amp;r2=1.104" source="CONFIRM">http://www.openbsd.org/cgi-bin/cvsweb/src/sys/net/pf_norm.c.diff?r1=1.103&amp;r2=1.104</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24337" source="XF">bsd-pf-fragment-dos(24337)</ref>
      <ref url="http://www.osvdb.org/22732" source="OSVDB">22732</ref>
      <ref url="http://securitytracker.com/id?1015542" source="SECTRACK">1015542</ref>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2006-004.txt.asc" source="NETBSD">NetBSD-SA2006-004</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="5.3" edition="release"/>
        <vers num="5.3" edition="releng"/>
        <vers num="5.3" edition="stable"/>
        <vers num="5.4" edition="pre-release"/>
        <vers num="5.4" edition="release"/>
        <vers num="5.4" edition="releng"/>
        <vers num="6.0" edition="release"/>
        <vers num="6.0" edition="stable"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0382" published="2006-02-14" name="CVE-2006-0382" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Apple Mac OS X 10.4.5 and allows local users to cause a denial of service (crash) via an undocumented system call.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0597" source="VUPEN">ADV-2006-0597</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/Feb/msg00000.html" source="APPLE">APPLE-SA-2006-02-14</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24682" source="XF">macosx-system-call-dos(24682)</ref>
      <ref url="http://www.securityfocus.com/bid/16654" source="BID">16654</ref>
      <ref url="http://www.osvdb.org/23190" source="OSVDB">23190</ref>
      <ref url="http://securitytracker.com/id?1015634" source="SECTRACK">1015634</ref>
      <ref url="http://secunia.com/advisories/18907" source="SECUNIA">18907</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0383" published="2006-03-02" name="CVE-2006-0383" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">IPSec when used with VPN networks in Mac OS X 10.4 through 10.4.5 allows remote attackers to cause a denial of service (application crash) via unspecified vectors involving the "incorrect handling of error conditions".</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-062A.html" source="CERT">TA06-062A</ref>
      <ref url="http://www.securityfocus.com/bid/16907" source="BID" patch="1">16907</ref>
      <ref url="http://secunia.com/advisories/19064" source="SECUNIA" patch="1" adv="1">19064</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0791" source="VUPEN">ADV-2006-0791</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/Mar/msg00000.html" source="APPLE">APPLE-SA-2006-03-01</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25025" source="XF">macosx-vpn-dos(25025)</ref>
      <ref url="http://www.osvdb.org/23643" source="OSVDB">23643</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=303382" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=303382</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3"/>
        <vers num="10.3.1"/>
        <vers num="10.3.2"/>
        <vers num="10.3.3"/>
        <vers num="10.3.4"/>
        <vers num="10.3.5"/>
        <vers num="10.3.6"/>
        <vers num="10.3.7"/>
        <vers num="10.3.8"/>
        <vers num="10.3.9"/>
        <vers num="10.4"/>
        <vers num="10.4.1"/>
        <vers num="10.4.2"/>
        <vers num="10.4.3"/>
        <vers num="10.4.4"/>
        <vers num="10.4.5"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3"/>
        <vers num="10.3.1"/>
        <vers num="10.3.2"/>
        <vers num="10.3.3"/>
        <vers num="10.3.4"/>
        <vers num="10.3.5"/>
        <vers num="10.3.6"/>
        <vers num="10.3.7"/>
        <vers num="10.3.8"/>
        <vers num="10.3.9"/>
        <vers num="10.4"/>
        <vers num="10.4.1"/>
        <vers num="10.4.2"/>
        <vers num="10.4.3"/>
        <vers num="10.4.4"/>
        <vers num="10.4.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0384" published="2006-03-02" name="CVE-2006-0384" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">automount in Mac OS X 10.4.5 and earlier allows remote file servers to cause a denial of service (unresponsiveness) or execute arbitrary code via unspecified vectors that cause automount to "mount file systems with reserved names".</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-062A.html" source="CERT">TA06-062A</ref>
      <ref url="http://www.securityfocus.com/bid/16907" source="BID" patch="1">16907</ref>
      <ref url="http://secunia.com/advisories/19064" source="SECUNIA" patch="1" adv="1">19064</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0791" source="VUPEN">ADV-2006-0791</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/Mar/msg00000.html" source="APPLE">APPLE-SA-2006-03-01</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25021" source="XF">macosx-automount-execute-code(25021)</ref>
      <ref url="http://www.osvdb.org/23640" source="OSVDB">23640</ref>
      <ref url="http://securitytracker.com/id?1015709" source="SECTRACK">1015709</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=303382" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=303382</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3"/>
        <vers num="10.3.1"/>
        <vers num="10.3.2"/>
        <vers num="10.3.3"/>
        <vers num="10.3.4"/>
        <vers num="10.3.5"/>
        <vers num="10.3.6"/>
        <vers num="10.3.7"/>
        <vers num="10.3.8"/>
        <vers num="10.3.9"/>
        <vers num="10.4"/>
        <vers num="10.4.1"/>
        <vers num="10.4.2"/>
        <vers num="10.4.3"/>
        <vers num="10.4.4"/>
        <vers num="10.4.5"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3"/>
        <vers num="10.3.1"/>
        <vers num="10.3.2"/>
        <vers num="10.3.3"/>
        <vers num="10.3.4"/>
        <vers num="10.3.5"/>
        <vers num="10.3.6"/>
        <vers num="10.3.7"/>
        <vers num="10.3.8"/>
        <vers num="10.3.9"/>
        <vers num="10.4"/>
        <vers num="10.4.1"/>
        <vers num="10.4.2"/>
        <vers num="10.4.3"/>
        <vers num="10.4.4"/>
        <vers num="10.4.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0386" published="2006-03-03" name="CVE-2006-0386" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="1.7" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.1" CVSS_base_score="1.7">
    <desc>
      <descript source="cve">FileVault in Mac OS X 10.4.5 and earlier does not properly mount user directories when creating a FileVault image, which allows local users to access protected files when FileVault is enabled.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-062A.html" source="CERT">TA06-062A</ref>
      <ref url="http://www.securityfocus.com/bid/16907" source="BID" patch="1">16907</ref>
      <ref url="http://secunia.com/advisories/19064" source="SECUNIA" patch="1" adv="1">19064</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/Mar/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2006-03-01</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0791" source="VUPEN">ADV-2006-0791</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25024" source="XF">macosx-filevault-file-access(25024)</ref>
      <ref url="http://www.osvdb.org/23642" source="OSVDB">23642</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=303382" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=303382</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3"/>
        <vers num="10.3.1"/>
        <vers num="10.3.2"/>
        <vers num="10.3.3"/>
        <vers num="10.3.4"/>
        <vers num="10.3.5"/>
        <vers num="10.3.6"/>
        <vers num="10.3.7"/>
        <vers num="10.3.8"/>
        <vers num="10.3.9"/>
        <vers num="10.4"/>
        <vers num="10.4.1"/>
        <vers num="10.4.2"/>
        <vers num="10.4.3"/>
        <vers num="10.4.4"/>
        <vers num="10.4.5"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3"/>
        <vers num="10.3.1"/>
        <vers num="10.3.2"/>
        <vers num="10.3.3"/>
        <vers num="10.3.4"/>
        <vers num="10.3.5"/>
        <vers num="10.3.6"/>
        <vers num="10.3.7"/>
        <vers num="10.3.8"/>
        <vers num="10.3.9"/>
        <vers num="10.4"/>
        <vers num="10.4.1"/>
        <vers num="10.4.2"/>
        <vers num="10.4.3"/>
        <vers num="10.4.4"/>
        <vers num="10.4.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0387" published="2006-03-06" name="CVE-2006-0387" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Safari in Mac OS X 10.4.5 and earlier, and 10.3.9 and earlier, allows remote attackers to execute arbitrary code via unspecified vectors involving a web page with crafted JavaScript, a different vulnerability than CVE-2005-4504.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-062A.html" source="CERT">TA06-062A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/176732" source="CERT-VN">VU#176732</ref>
      <ref url="http://www.securityfocus.com/bid/16907" source="BID" patch="1" adv="1">16907</ref>
      <ref url="http://secunia.com/advisories/19064" source="SECUNIA" patch="1" adv="1">19064</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/Mar/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2006-03-01</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0791" source="VUPEN">ADV-2006-0791</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25032" source="XF">macosx-safari-bo(25032)</ref>
      <ref url="http://securitytracker.com/id?1015713" source="SECTRACK">1015713</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=303382" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=303382</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3"/>
        <vers num="10.3.1"/>
        <vers num="10.3.2"/>
        <vers num="10.3.3"/>
        <vers num="10.3.4"/>
        <vers num="10.3.5"/>
        <vers num="10.3.6"/>
        <vers num="10.3.7"/>
        <vers num="10.3.8"/>
        <vers num="10.3.9"/>
        <vers num="10.4"/>
        <vers num="10.4.1"/>
        <vers num="10.4.2"/>
        <vers num="10.4.3"/>
        <vers num="10.4.4"/>
        <vers num="10.4.5"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3"/>
        <vers num="10.3.1"/>
        <vers num="10.3.2"/>
        <vers num="10.3.3"/>
        <vers num="10.3.4"/>
        <vers num="10.3.5"/>
        <vers num="10.3.6"/>
        <vers num="10.3.7"/>
        <vers num="10.3.8"/>
        <vers num="10.3.9"/>
        <vers num="10.4"/>
        <vers num="10.4.1"/>
        <vers num="10.4.2"/>
        <vers num="10.4.3"/>
        <vers num="10.4.4"/>
        <vers num="10.4.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0388" published="2006-03-03" name="CVE-2006-0388" modified="2011-08-08" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:P)" CVSS_score="2.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="1.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Safari in Mac OS X 10.3 before 10.3.9 and 10.4 before 10.4.5 allows remote attackers to redirect users to local files and execute arbitrary JavaScript via unspecified vectors involving HTTP redirection to local resources.</descript>
    </desc>
    <loss_types>
      <avail/>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-062A.html" source="CERT">TA06-062A</ref>
      <ref url="http://www.securityfocus.com/bid/16907" source="BID" patch="1">16907</ref>
      <ref url="http://securitytracker.com/id?1015713" source="SECTRACK" patch="1">1015713</ref>
      <ref url="http://secunia.com/advisories/19064" source="SECUNIA" patch="1" adv="1">19064</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/Mar/msg00000.html" source="APPLE" patch="1">APPLE-SA-2006-03-01</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25038" source="XF">macosx-safari-http-redirect(25038)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0791" source="VUPEN" adv="1">ADV-2006-0791</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=303382" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=303382</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3"/>
        <vers num="10.3.1"/>
        <vers num="10.3.2"/>
        <vers num="10.3.3"/>
        <vers num="10.3.4"/>
        <vers num="10.3.5"/>
        <vers num="10.3.6"/>
        <vers num="10.3.7"/>
        <vers num="10.3.8"/>
        <vers num="10.3.9"/>
        <vers num="10.4"/>
        <vers num="10.4.1"/>
        <vers num="10.4.2"/>
        <vers num="10.4.3"/>
        <vers num="10.4.4"/>
        <vers num="10.4.5"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.3"/>
        <vers num="10.3.1"/>
        <vers num="10.3.2"/>
        <vers num="10.3.3"/>
        <vers num="10.3.4"/>
        <vers num="10.3.5"/>
        <vers num="10.3.6"/>
        <vers num="10.3.7"/>
        <vers num="10.3.8"/>
        <vers num="10.3.9"/>
        <vers num="10.4"/>
        <vers num="10.4.1"/>
        <vers num="10.4.2"/>
        <vers num="10.4.3"/>
        <vers num="10.4.4"/>
        <vers num="10.4.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0389" published="2006-03-03" name="CVE-2006-0389" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Syndication (Safari RSS) in Mac OS X 10.4 through 10.4.5 allows remote attackers to execute arbitrary JavaScript via unspecified vectors involving RSS feeds.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-062A.html" source="CERT">TA06-062A</ref>
      <ref url="http://www.securityfocus.com/bid/16907" source="BID" patch="1">16907</ref>
      <ref url="http://secunia.com/advisories/19064" source="SECUNIA" patch="1" adv="1">19064</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/Mar/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2006-03-01</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0791" source="VUPEN">ADV-2006-0791</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25040" source="XF">macosx-syndication-xss(25040)</ref>
      <ref url="http://www.osvdb.org/23649" source="OSVDB">23649</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=303382" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=303382</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4"/>
        <vers num="10.4.1"/>
        <vers num="10.4.2"/>
        <vers num="10.4.3"/>
        <vers num="10.4.4"/>
        <vers num="10.4.5"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4"/>
        <vers num="10.4.1"/>
        <vers num="10.4.2"/>
        <vers num="10.4.3"/>
        <vers num="10.4.4"/>
        <vers num="10.4.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2006-0390" reject="1" published="2006-03-06" name="CVE-2006-0390" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2005-4504.  Reason: This candidate is a duplicate of CVE-2005-4504.  Notes: All CVE users should reference CVE-2005-4504 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0391" published="2006-03-03" name="CVE-2006-0391" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:S/C:N/I:P/A:N)" CVSS_score="1.7" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.1" CVSS_base_score="1.7">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the BOM framework in Mac OS X 10.x before 10.3.9 and 10.4 before 10.4.5 allows user-assisted attackers to overwrite or create arbitrary files via an archive that is handled by BOMArchiveHelper.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-062A.html" source="CERT">TA06-062A</ref>
      <ref url="http://www.idefense.com/intelligence/vulnerabilities/display.php?id=399" source="IDEFENSE" patch="1" adv="1">20060302 Apple MacOS X BOMArchiveHelper Directory Traversal Vulnerability</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/Mar/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2006-03-01</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0791" source="VUPEN">ADV-2006-0791</ref>
      <ref url="http://www.securityfocus.com/bid/16907" source="BID">16907</ref>
      <ref url="http://www.osvdb.org/23641" source="OSVDB">23641</ref>
      <ref url="http://secunia.com/advisories/19064" source="SECUNIA">19064</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25023" source="XF">macosx-bom-directory-traversal(25023)</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=303382" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=303382</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.3.1"/>
        <vers num="10.3.3"/>
        <vers num="10.3.4"/>
        <vers num="10.3.5"/>
        <vers num="10.3.6"/>
        <vers num="10.3.7"/>
        <vers num="10.3.8"/>
        <vers num="10.4"/>
        <vers num="10.4.1"/>
        <vers num="10.4.2"/>
        <vers num="10.4.3"/>
        <vers num="10.4.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0392" published="2006-08-02" name="CVE-2006-0392" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Buffer overflow in Apple Mac OS X 10.4.7 allows user-assisted attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted Canon RAW image.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/527236" source="CERT-VN">VU#527236</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-214A.html" source="CERT">TA06-214A</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/28142" source="XF">macosx-raw-image-bo(28142)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3101" source="VUPEN">ADV-2006-3101</ref>
      <ref url="http://www.securityfocus.com/bid/19289" source="BID">19289</ref>
      <ref url="http://www.osvdb.org/27739" source="OSVDB">27739</ref>
      <ref url="http://secunia.com/advisories/21253" source="SECUNIA">21253</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006//Aug/msg00000.html" source="APPLE">APPLE-SA-2006-08-01</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.7"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0393" published="2006-08-02" name="CVE-2006-0393" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:P)" CVSS_score="4.0" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="4.9" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">OpenSSH in Apple Mac OS X 10.4.7 allows remote attackers to cause a denial of service or determine account existence by attempting to log in using an invalid user, which causes the server to hang.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-214A.html" source="CERT">TA06-214A</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/28147" source="XF">macosx-openssh-nonexistent-user-dos(28147)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/3101" source="VUPEN">ADV-2006-3101</ref>
      <ref url="http://www.securityfocus.com/bid/19289" source="BID">19289</ref>
      <ref url="http://www.osvdb.org/27745" source="OSVDB">27745</ref>
      <ref url="http://securitytracker.com/id?1016672" source="SECTRACK">1016672</ref>
      <ref url="http://secunia.com/advisories/21253" source="SECUNIA">21253</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006//Aug/msg00000.html" source="APPLE">APPLE-SA-2006-08-01</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.7"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2006-0394" reject="1" published="2006-03-01" name="CVE-2006-0394" modified="2008-09-10">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2006-0848.  Reason: This candidate is a duplicate of CVE-2006-0848.  Notes: All CVE users should reference CVE-2006-0848 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs/>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0395" published="2006-08-04" name="CVE-2006-0395" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">The Download Validation in Mail in Mac OS X 10.4 does not properly recognize attachment file types to warn a user of an unsafe type, which allows user-assisted remote attackers to execute arbitrary code via crafted file types.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-062A.html" source="CERT">TA06-062A</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0791" source="VUPEN">ADV-2006-0791</ref>
      <ref url="http://lists.apple.com/archives/client-management/2006/Mar/msg00030.html" source="APPLE">APPLE-SA-2006-03-01</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=303382" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=303382</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25027" source="XF">macosx-mail-bypass-security(25027)</ref>
      <ref url="http://www.securityfocus.com/bid/16907" source="BID">16907</ref>
      <ref url="http://www.osvdb.org/23645" source="OSVDB">23645</ref>
      <ref url="http://secunia.com/advisories/19064" source="SECUNIA">19064</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.5"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0396" published="2006-03-14" name="CVE-2006-0396" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Buffer overflow in Mail in Apple Mac OS X 10.4 up to 10.4.5, when patched with Security Update 2006-001, allows remote attackers to execute arbitrary code via a long Real Name value in an e-mail attachment sent in AppleDouble format, which triggers the overflow when the user double-clicks on an attachment.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/980084" source="CERT-VN">VU#980084</ref>
      <ref url="http://www.securityfocus.com/bid/17081" source="BID" patch="1">17081</ref>
      <ref url="http://securitytracker.com/id?1015762" source="SECTRACK" patch="1">1015762</ref>
      <ref url="http://secunia.com/advisories/19129" source="SECUNIA" patch="1" adv="1">19129</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0949" source="VUPEN">ADV-2006-0949</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427601/100/0/threaded" source="BUGTRAQ" adv="1">20060314 DMA[2006-0313a] - 'Apple OSX Mail.app RFC1740 Real Name Buffer Overflow'</ref>
      <ref url="http://www.digitalmunition.com/DMA%5B2006-0313a%5D.txt" source="MISC" adv="1">http://www.digitalmunition.com/DMA%5B2006-0313a%5D.txt</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/Mar/msg00001.html" source="APPLE">APPLE-SA-2006-03-13</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=303453" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=303453</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25209" source="XF">macosx-mail-attachment-bo(25209)</ref>
      <ref url="http://www.osvdb.org/23872" source="OSVDB">23872</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4"/>
        <vers num="10.4.1"/>
        <vers num="10.4.2"/>
        <vers num="10.4.3"/>
        <vers num="10.4.4"/>
        <vers num="10.4.5"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4"/>
        <vers num="10.4.1"/>
        <vers num="10.4.2"/>
        <vers num="10.4.3"/>
        <vers num="10.4.4"/>
        <vers num="10.4.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0397" published="2006-03-14" name="CVE-2006-0397" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in Safari, LaunchServices, and/or CoreTypes in Apple Mac OS X 10.4 up to 10.4.5 allows attackers to trick a user into opening an application that appears to be a safe file type. NOTE: due to the lack of specific information in the vendor advisory, it is not clear how CVE-2006-0397, CVE-2006-0398, and CVE-2006-0399 are different.</descript>
      <descript source="nvd">Per Hyperlink 894663:
Vendor description specifies that the file is automatically opened by the application: Safari could automatically open a file which appears to be a safe file type.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/19129" source="SECUNIA" patch="1" adv="1">19129</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25269" source="XF">macosx-safefiletype-command-execution(25269)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0949" source="VUPEN">ADV-2006-0949</ref>
      <ref url="http://www.osvdb.org/23869" source="OSVDB">23869</ref>
      <ref url="http://securitytracker.com/id?1015760" source="SECTRACK">1015760</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/Mar/msg00001.html" source="APPLE">APPLE-SA-2006-03-13</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=303453" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=303453</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4"/>
        <vers num="10.4.1"/>
        <vers num="10.4.2"/>
        <vers num="10.4.3"/>
        <vers num="10.4.4"/>
        <vers num="10.4.5"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4"/>
        <vers num="10.4.1"/>
        <vers num="10.4.2"/>
        <vers num="10.4.3"/>
        <vers num="10.4.4"/>
        <vers num="10.4.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0398" published="2006-03-14" name="CVE-2006-0398" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in Safari, LaunchServices, and/or CoreTypes in Apple Mac OS X 10.4 up to 10.4.5 allows attackers to trick a user into opening an application that appears to be a safe file type. NOTE: due to the lack of specific information in the vendor advisory, it is not clear how CVE-2006-0397, CVE-2006-0398, and CVE-2006-0399 are different.</descript>
      <descript source="nvd">Hyperlink Record 894667 specifies: Safari could automatically open a file which appears to be a safe file type, such as an image or movie, but is actually an application.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/19129" source="SECUNIA" patch="1" adv="1">19129</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25269" source="XF">macosx-safefiletype-command-execution(25269)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0949" source="VUPEN">ADV-2006-0949</ref>
      <ref url="http://www.osvdb.org/23870" source="OSVDB">23870</ref>
      <ref url="http://securitytracker.com/id?1015760" source="SECTRACK">1015760</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/Mar/msg00001.html" source="APPLE">APPLE-SA-2006-03-13</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=303453" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=303453</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4"/>
        <vers num="10.4.1"/>
        <vers num="10.4.2"/>
        <vers num="10.4.3"/>
        <vers num="10.4.4"/>
        <vers num="10.4.5"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4"/>
        <vers num="10.4.1"/>
        <vers num="10.4.2"/>
        <vers num="10.4.3"/>
        <vers num="10.4.4"/>
        <vers num="10.4.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0399" published="2006-03-14" name="CVE-2006-0399" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in Safari, LaunchServices, and/or CoreTypes in Apple Mac OS X 10.4 up to 10.4.5 allows attackers to trick a user into opening an application that appears to be a safe file type. NOTE: due to the lack of specific information in the vendor advisory, it is not clear how CVE-2006-0397, CVE-2006-0398, and CVE-2006-0399 are different.</descript>
      <descript source="nvd">Per Hyperlink Record 894671:
Safari could automatically open a file which appears to be a safe file type, such as an image or movie, but is actually an application.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/19129" source="SECUNIA" patch="1" adv="1">19129</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25269" source="XF">macosx-safefiletype-command-execution(25269)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0949" source="VUPEN">ADV-2006-0949</ref>
      <ref url="http://www.osvdb.org/23871" source="OSVDB">23871</ref>
      <ref url="http://securitytracker.com/id?1015760" source="SECTRACK">1015760</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/Mar/msg00001.html" source="APPLE">APPLE-SA-2006-03-13</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=303453" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=303453</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4"/>
        <vers num="10.4.1"/>
        <vers num="10.4.2"/>
        <vers num="10.4.3"/>
        <vers num="10.4.4"/>
        <vers num="10.4.5"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4"/>
        <vers num="10.4.1"/>
        <vers num="10.4.2"/>
        <vers num="10.4.3"/>
        <vers num="10.4.4"/>
        <vers num="10.4.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0400" published="2006-03-14" name="CVE-2006-0400" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">CoreTypes in Apple Mac OS X 10.4 up to 10.4.5 allows remote attackers to bypass the same-origin policy and execute Javascript in other domains via unknown vectors involving "crafted archives."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <access/>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/17082" source="BID" patch="1">17082</ref>
      <ref url="http://secunia.com/advisories/19129" source="SECUNIA" patch="1" adv="1">19129</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0949" source="VUPEN">ADV-2006-0949</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2006/Mar/msg00001.html" source="APPLE">APPLE-SA-2006-03-13</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=303453" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=303453</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25208" source="XF">macosx-sameorigin-policy-bypass(25208)</ref>
      <ref url="http://www.osvdb.org/23873" source="OSVDB">23873</ref>
      <ref url="http://securitytracker.com/id?1015763" source="SECTRACK">1015763</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4"/>
        <vers num="10.4.1"/>
        <vers num="10.4.2"/>
        <vers num="10.4.3"/>
        <vers num="10.4.4"/>
        <vers num="10.4.5"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4"/>
        <vers num="10.4.1"/>
        <vers num="10.4.2"/>
        <vers num="10.4.3"/>
        <vers num="10.4.4"/>
        <vers num="10.4.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0401" published="2006-04-05" name="CVE-2006-0401" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Unspecified vulnerability in Mac OS X before 10.4.6, when running on an Intel-based computer, allows attackers with physical access to bypass the firmware password and log on in Single User Mode via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/19462" source="SECUNIA" patch="1" adv="1">19462</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1215" source="VUPEN">ADV-2006-1215</ref>
      <ref url="http://www.securityfocus.com/bid/17364" source="BID">17364</ref>
      <ref url="http://docs.info.apple.com/article.html?artnum=303567" source="CONFIRM">http://docs.info.apple.com/article.html?artnum=303567</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25620" source="XF">macosx-firmware-password-bypass(25620)</ref>
      <ref url="http://www.osvdb.org/24399" source="OSVDB">24399</ref>
      <ref url="http://securitytracker.com/id?1015859" source="SECTRACK">1015859</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.5"/>
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0402" published="2006-01-24" name="CVE-2006-0402" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in Zoph before 0.5pre1 allows remote attackers to execute arbitrary SQL commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24264" source="XF" patch="1">zoph-sql-injection(24264)</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=69353&amp;release_id=387320" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?group_id=69353&amp;release_id=387320</ref>
      <ref url="http://secunia.com/advisories/18563" source="SECUNIA" patch="1" adv="1">18563</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0297" source="VUPEN">ADV-2006-0297</ref>
      <ref url="http://www.securityfocus.com/bid/16347" source="BID">16347</ref>
      <ref url="http://www.osvdb.org/22743" source="OSVDB">22743</ref>
      <ref url="http://www.debian.org/security/2006/dsa-989" source="DEBIAN">DSA-989</ref>
      <ref url="http://secunia.com/advisories/19153" source="SECUNIA">19153</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jason_geiger" name="zoph">
        <vers num="0.3.3"/>
        <vers num="0.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0403" published="2006-01-24" name="CVE-2006-0403" modified="2011-09-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in e-moBLOG 1.3 allow remote attackers to execute arbitrary SQL commands via the (1) monthy parameter to index.php or (2) login parameter to admin/index.php. NOTE: some sources have reported item 1 as involving the "monthly" parameter, but this is incorrect.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24245" source="XF">emoblog-index-sql-injection(24245)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0296" source="VUPEN" adv="1">ADV-2006-0296</ref>
      <ref url="http://www.securityfocus.com/bid/16344" source="BID">16344</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422938/100/0/threaded" source="BUGTRAQ">20060122 [eVuln] e-moBLOG SQL Injection Vulnerability</ref>
      <ref url="http://www.osvdb.org/22701" source="OSVDB">22701</ref>
      <ref url="http://www.osvdb.org/22700" source="OSVDB">22700</ref>
      <ref url="http://securitytracker.com/id?1015524" source="SECTRACK">1015524</ref>
      <ref url="http://securityreason.com/securityalert/370" source="SREASON">370</ref>
      <ref url="http://secunia.com/advisories/18567" source="SECUNIA" adv="1">18567</ref>
      <ref url="http://evuln.com/vulns/43/summary.html" source="MISC" adv="1">http://evuln.com/vulns/43/summary.html</ref>
      <ref url="http://attrition.org/pipermail/vim/2006-January/000511.html" source="VIM">20060125 The parameter in e-moBLOG is </ref>
    </refs>
    <vuln_soft>
      <prod vendor="e-moblog" name="e-moblog">
        <vers num="1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0404" published="2006-01-24" name="CVE-2006-0404" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Note-A-Day Weblog 2.2 stores sensitive data under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to archive/.phpass-admin, which contains encrypted passwords.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <config/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24270" source="XF">noteaday-archive-directory-insecure(24270)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24270" source="XF">noteaday-archive-information-disclosure(24270)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0299" source="VUPEN">ADV-2006-0299</ref>
      <ref url="http://secunia.com/advisories/18566" source="SECUNIA" adv="1">18566</ref>
      <ref url="http://evuln.com/vulns/44/summary.html" source="MISC" adv="1">http://evuln.com/vulns/44/summary.html</ref>
      <ref url="http://www.osvdb.org/22699" source="OSVDB">22699</ref>
      <ref url="http://securitytracker.com/id?1015539" source="SECTRACK">1015539</ref>
      <ref url="http://securityreason.com/securityalert/371" source="SREASON">371</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2006-01/0389.html" source="BUGTRAQ">20060122 [eVuln] Note-A-Day Weblog Sensitive Information Disclosure</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mike_macgirvin" name="note-a-day_weblog">
        <vers num="2.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0405" published="2006-01-24" name="CVE-2006-0405" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The TIFFFetchShortPair function in tif_dirread.c in libtiff 3.8.0 allows remote attackers to cause a denial of service (application crash) via a crafted TIFF image that triggers a NULL pointer dereference, possibly due to changes in type declarations and/or the TIFFVSetField function.</descript>
      <descript source="nvd">Per: http://cwe.mitre.org/data/definitions/476.html
'CWE-476: NULL Pointer Dereference'</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24275" source="XF">libtiff-tiffvsetfield-dos(24275)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0302" source="VUPEN" adv="1">ADV-2006-0302</ref>
      <ref url="http://www.securityfocus.com/bid/18172" source="BID">18172</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200605-17.xml" source="GENTOO">GLSA-200605-17</ref>
      <ref url="http://secunia.com/advisories/20345" source="SECUNIA" adv="1">20345</ref>
      <ref url="http://secunia.com/advisories/18587" source="SECUNIA" adv="1">18587</ref>
      <ref url="http://bugzilla.remotesensing.org/show_bug.cgi?id=1034" source="MISC">http://bugzilla.remotesensing.org/show_bug.cgi?id=1034</ref>
      <ref url="http://bugzilla.remotesensing.org/show_bug.cgi?id=1029" source="MISC">http://bugzilla.remotesensing.org/show_bug.cgi?id=1029</ref>
    </refs>
    <vuln_soft>
      <prod vendor="libtiff" name="libtiff">
        <vers num="3.8.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0406" published="2006-01-24" name="CVE-2006-0406" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">search.php in MyBB 1.0.2 allows remote attackers to obtain sensitive information via a certain search request that reveals the table prefix in a SQL error message, possibly due to invalid parameters.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24272" source="XF">mybb-search-information-disclosure(24272)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422227/100/0/threaded" source="BUGTRAQ" adv="1">20060114 MyBB 1.0.2 Sniffing table perfix bug in search.php</ref>
      <ref url="http://www.osvdb.org/22736" source="OSVDB">22736</ref>
      <ref url="http://secunia.com/advisories/18577" source="SECUNIA" adv="1">18577</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mybulletinboard" name="mybulletinboard">
        <vers num="1.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0407" published="2006-01-24" name="CVE-2006-0407" modified="2011-03-07" discovered="2006-01-20" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in post.php in AZ Bulletin Board (AZbb) 1.1.00 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) nickname parameter and (2) an iframe tag in the topic parameter.  NOTE: the original disclosure specified the name parameter, but a correction was later provided. NOTE: followup posts have both disputed and confirmed the original claim.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24274" source="XF">azbulletinboard-post-xss(24274)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0298" source="VUPEN">ADV-2006-0298</ref>
      <ref url="http://www.securityfocus.com/bid/16351" source="BID">16351</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427194/100/0/threaded" source="BUGTRAQ">20060309 Re: Re: [CORRECTIONS AND ADDITIONS ]Azbb v1.1.00 Cross-Site Scripting</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427076/100/0/threaded" source="BUGTRAQ">20060308 Re: [CORRECTIONS AND ADDITIONS ]Azbb v1.1.00 Cross-Site Scripting </ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423363/100/0/threaded" source="BUGTRAQ">20060128 [CORRECTIONS AND ADDITIONS ]Azbb v1.1.00 Cross-Site Scripting</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423353/100/0/threaded" source="BUGTRAQ" adv="1">20060123 Azbb v1.1.00 Cross-Site Scripting</ref>
      <ref url="http://secunia.com/advisories/18565" source="SECUNIA" adv="1">18565</ref>
      <ref url="http://kapda.ir/advisory-236.html" source="MISC" adv="1">http://kapda.ir/advisory-236.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427076/30/6510/threaded" source="BUGTRAQ">20060308 Re: [CORRECTIONS AND ADDITIONS ]Azbb v1.1.00 Cross-Site Scripting</ref>
    </refs>
    <vuln_soft>
      <prod vendor="azbb" name="az_bulletin_board">
        <vers num="1.0.0"/>
        <vers num="1.0.0rc1"/>
        <vers num="1.0.0rc2"/>
        <vers num="1.0.1"/>
        <vers num="1.0.10"/>
        <vers num="1.0.11"/>
        <vers num="1.0.12"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.0.9"/>
        <vers num="1.1.00"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0408" published="2006-01-24" name="CVE-2006-0408" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">rsh utility in Sun Grid Engine (SGE) before 6.0u7_1 allows local users to gain privileges and execute arbitrary code via unspecified vectors, possibly involving command line arguments.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18580" source="SECUNIA" patch="1" adv="1">18580</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0308" source="VUPEN">ADV-2006-0308</ref>
      <ref url="http://gridengine.sunsource.net/project/gridengine/60patches.txt" source="CONFIRM">http://gridengine.sunsource.net/project/gridengine/60patches.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24281" source="XF">sge-rsh-gain-privileges(24281)</ref>
      <ref url="http://www.securityfocus.com/bid/16366" source="BID">16366</ref>
      <ref url="http://securitytracker.com/id?1015531" source="SECTRACK">1015531</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="grid_engine">
        <vers num="6.0" edition="update1"/>
        <vers num="6.0" edition="update2"/>
        <vers num="6.0" edition="update3"/>
        <vers num="6.0" edition="update4"/>
        <vers num="6.0" edition="update5"/>
        <vers num="6.0" edition="update6"/>
        <vers num="6.0" edition="update7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0409" published="2006-01-24" name="CVE-2006-0409" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Pixelpost Photoblog 1.4.3 allows remote attackers to inject arbitrary web script or HTML via the "Add Comment" field in a comment popup.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24261" source="XF">pixelpost-index-xss(24261)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0309" source="VUPEN">ADV-2006-0309</ref>
      <ref url="http://www.securityfocus.com/bid/16362" source="BID">16362</ref>
      <ref url="http://secunia.com/advisories/18572" source="SECUNIA" adv="1">18572</ref>
      <ref url="http://evuln.com/vulns/45/summary.html" source="MISC" adv="1">http://evuln.com/vulns/45/summary.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423384/100/0/threaded" source="BUGTRAQ">20060123 [eVuln] Pixelpost Photoblog XSS Vulnerability</ref>
      <ref url="http://securitytracker.com/id?1015529" source="SECTRACK">1015529</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pixelpost" name="photoblog">
        <vers num="1.4.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0410" published="2006-01-24" name="CVE-2006-0410" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in ADOdb before 4.71, when using PostgreSQL, allows remote attackers to execute arbitrary SQL commands via unspecified attack vectors involving binary strings.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=387862&amp;group_id=42718" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=387862&amp;group_id=42718</ref>
      <ref url="http://secunia.com/advisories/18575" source="SECUNIA" patch="1" adv="1">18575</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24314" source="XF">adodb-postgresql-sql-injection(24314)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0448" source="VUPEN">ADV-2006-0448</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0315" source="VUPEN">ADV-2006-0315</ref>
      <ref url="http://www.securityfocus.com/bid/16364" source="BID">16364</ref>
      <ref url="http://www.osvdb.org/22705" source="OSVDB">22705</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200604-07.xml" source="GENTOO">GLSA-200604-07</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200602-02.xml" source="GENTOO">GLSA-200602-02</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1031" source="DEBIAN">DSA-1031</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1030" source="DEBIAN">DSA-1030</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1029" source="DEBIAN">DSA-1029</ref>
      <ref url="http://secunia.com/advisories/19591" source="SECUNIA">19591</ref>
      <ref url="http://secunia.com/advisories/19590" source="SECUNIA">19590</ref>
      <ref url="http://secunia.com/advisories/19555" source="SECUNIA">19555</ref>
      <ref url="http://secunia.com/advisories/18745" source="SECUNIA">18745</ref>
      <ref url="http://secunia.com/advisories/18732" source="SECUNIA">18732</ref>
      <ref url="http://secunia.com/advisories/19691" source="SECUNIA">19691</ref>
    </refs>
    <vuln_soft>
      <prod vendor="john_lim" name="adodb">
        <vers num="4.66"/>
        <vers num="4.68"/>
        <vers num="4.70"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0411" published="2006-01-25" name="CVE-2006-0411" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">claro_init_local.inc.php in Claroline 1.7.2 uses guessable session cookies (MD5 hash of connection time), which allows remote attackers to hijack sessions and possibly gain administrative privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0320" source="VUPEN">ADV-2006-0320</ref>
      <ref url="http://www.securityfocus.com/bid/16341" source="BID">16341</ref>
      <ref url="http://www.securityfocus.com/archive/1/422482" source="BUGTRAQ">20060120 Claroline 1.7.2, sso identification vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24326" source="XF">claroline-cookie-bypass-security(24326)</ref>
      <ref url="http://secunia.com/advisories/18588" source="SECUNIA">18588</ref>
    </refs>
    <vuln_soft>
      <prod vendor="claroline" name="claroline">
        <vers num="1.7.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0412" published="2006-01-25" name="CVE-2006-0412" modified="2012-08-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in CyberShop allows remote attackers to execute arbitrary SQL commands and bypass authentication via the username parameter in a login action.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24005" source="XF">cybershop-login-sql-injection(24005)</ref>
      <ref url="http://www.osvdb.org/22365" source="OSVDB">22365</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2006-01/0064.html" source="BUGTRAQ">20060105 CyberShop User Login Sql Injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gencbeyin_web_programlama" name="cybershop">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0413" published="2006-01-25" name="CVE-2006-0413" modified="2011-09-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in index.php in NewsPHP allow remote attackers to execute arbitrary SQL commands via the (1) discuss, (2) tim, (3) id, (4) last, and (5) limit parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24320" source="XF">newsphp-index-sql-injection(24320)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0341" source="VUPEN" adv="1">ADV-2006-0341</ref>
      <ref url="http://www.securityfocus.com/bid/16339" source="BID">16339</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423129/100/0/threaded" source="BUGTRAQ">20060122 Newsphp Multiple SQL Injection Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/22717" source="OSVDB">22717</ref>
      <ref url="http://secunia.com/advisories/18624" source="SECUNIA" adv="1">18624</ref>
    </refs>
    <vuln_soft>
      <prod vendor="newsphp" name="newsphp">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0414" published="2006-01-25" name="CVE-2006-0414" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Tor before 0.1.1.20 allows remote attackers to identify hidden services via a malicious Tor server that attempts a large number of accesses of the hidden service, which eventually causes a circuit to be built through the malicious server.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18576" source="SECUNIA" patch="1" adv="1">18576</ref>
      <ref url="http://archives.seul.org/or/announce/Jan-2006/msg00001.html" source="CONFIRM" patch="1" adv="1">http://archives.seul.org/or/announce/Jan-2006/msg00001.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24285" source="XF">tor-service-information-disclosure(24285)</ref>
      <ref url="http://www.securityfocus.com/bid/18323" source="BID">18323</ref>
      <ref url="http://www.osvdb.org/22689" source="OSVDB">22689</ref>
      <ref url="http://tor.eff.org/cvs/tor/ChangeLog" source="CONFIRM">http://tor.eff.org/cvs/tor/ChangeLog</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200606-04.xml" source="GENTOO">GLSA-200606-04</ref>
      <ref url="http://secunia.com/advisories/20514" source="SECUNIA">20514</ref>
      <ref url="http://www.securityfocus.com/bid/19795" source="BID">19795</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tor" name="tor">
        <vers num="0.0.2"/>
        <vers num="0.0.2_pre13"/>
        <vers num="0.0.2_pre14"/>
        <vers num="0.0.2_pre15"/>
        <vers num="0.0.2_pre16"/>
        <vers num="0.0.2_pre17"/>
        <vers num="0.0.2_pre18"/>
        <vers num="0.0.2_pre19"/>
        <vers num="0.0.2_pre20"/>
        <vers num="0.0.2_pre21"/>
        <vers num="0.0.2_pre22"/>
        <vers num="0.0.2_pre23"/>
        <vers num="0.0.2_pre24"/>
        <vers num="0.0.2_pre25"/>
        <vers num="0.0.2_pre26"/>
        <vers num="0.0.2_pre27"/>
        <vers num="0.0.3"/>
        <vers num="0.0.4"/>
        <vers num="0.0.5"/>
        <vers num="0.0.6"/>
        <vers num="0.0.6.1"/>
        <vers num="0.0.6.2"/>
        <vers num="0.0.7"/>
        <vers num="0.0.7.1"/>
        <vers num="0.0.7.2"/>
        <vers num="0.0.7.3"/>
        <vers num="0.0.8"/>
        <vers num="0.0.8.1"/>
        <vers num="0.0.9"/>
        <vers num="0.0.9.1"/>
        <vers num="0.0.9.10"/>
        <vers num="0.0.9.2"/>
        <vers num="0.0.9.3"/>
        <vers num="0.0.9.4"/>
        <vers num="0.0.9.5"/>
        <vers num="0.0.9.6"/>
        <vers num="0.0.9.7"/>
        <vers num="0.0.9.8"/>
        <vers num="0.0.9.9"/>
        <vers num="0.1.0.10"/>
        <vers num="0.1.0.11"/>
        <vers num="0.1.0.12"/>
        <vers num="0.1.0.13"/>
        <vers num="0.1.0.14"/>
        <vers num="0.1.0.15"/>
        <vers num="0.1.0.16"/>
        <vers num="0.1.0.17"/>
        <vers num="0.1.1.10_alpha"/>
        <vers num="0.1.1.1_alpha"/>
        <vers num="0.1.1.2_alpha"/>
        <vers num="0.1.1.3_alpha"/>
        <vers num="0.1.1.4_alpha"/>
        <vers num="0.1.1.5_alpha"/>
        <vers num="0.1.1.6_alpha"/>
        <vers num="0.1.1.7_alpha"/>
        <vers num="0.1.1.8_alpha"/>
        <vers num="0.1.1.9_alpha"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0415" published="2006-01-25" name="CVE-2006-0415" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in SleeperChat 0.3f and earlier allows remote attackers to inject arbitrary web script or HTML via the pseudo parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16363" source="BID">16363</ref>
      <ref url="http://securitytracker.com/id?1015525" source="SECTRACK">1015525</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24300" source="XF">sleeperchat-index-xss(24300)</ref>
      <ref url="http://www.osvdb.org/22784" source="OSVDB">22784</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sleeperchat" name="sleeperchat">
        <vers prev="1" num="0.3f"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0416" published="2006-01-25" name="CVE-2006-0416" modified="2008-09-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">SleeperChat 0.3f and earlier allows remote attackers to bypass authentication and create new entries via the txt parameter to (1) chat_no.php and (2) chat_if.php.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24357" source="XF">sleeperchat-txt-security-bypass(24357)</ref>
      <ref url="http://securitytracker.com/id?1015525" source="SECTRACK">1015525</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sleeperchat" name="sleeperchat">
        <vers prev="1" num="0.3f"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0417" published="2006-01-25" name="CVE-2006-0417" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in login.php in miniBloggie 1.0 and earlier, when gpc_magic_quotes is disabled, allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username and (2) password parameters.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0310" source="VUPEN">ADV-2006-0310</ref>
      <ref url="http://evuln.com/vulns/47/summary.html" source="MISC" adv="1">http://evuln.com/vulns/47/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24280" source="XF">minibloggie-login-sql-injection(24280)</ref>
      <ref url="http://www.securityfocus.com/bid/16367" source="BID">16367</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423126/100/0/threaded" source="BUGTRAQ">20060124 [eVuln] miniBloggie Authentication Bypass</ref>
      <ref url="http://www.osvdb.org/22729" source="OSVDB">22729</ref>
      <ref url="http://securitytracker.com/id?1015534" source="SECTRACK">1015534</ref>
      <ref url="http://secunia.com/advisories/18604" source="SECUNIA">18604</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mywebland" name="minibloggie">
        <vers prev="1" num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0418" published="2006-01-25" name="CVE-2006-0418" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Eval injection vulnerability in 123 Flash Chat Server 5.0 and 5.1 allows attackers to execute arbitrary code via a crafted username.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16360" source="BID" patch="1">16360</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423164/100/0/threaded" source="BUGTRAQ" adv="1">20060124 [ISecAuditors Advisories] Arbitrary flash code remote execution in 123flashchat</ref>
    </refs>
    <vuln_soft>
      <prod vendor="topcmm_computing" name="123_flash_chat_server">
        <vers num="5.0"/>
        <vers num="5.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0419" published="2006-01-25" name="CVE-2006-0419" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">BEA WebLogic Server and WebLogic Express 9.0, 8.1 through SP5, and 7.0 through SP6 allows anonymous binds to the embedded LDAP server, which allows remote attackers to read user entries or cause a denial of service (unspecified) via a large number of connections.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1015528" source="SECTRACK" patch="1">1015528</ref>
      <ref url="http://dev2dev.bea.com/pub/advisory/163" source="BEA" adv="1">BEA06-81.01</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="7.0" edition="sp1"/>
        <vers num="7.0" edition="sp1:express"/>
        <vers num="7.0" edition="sp2"/>
        <vers num="7.0" edition="sp2:express"/>
        <vers num="7.0" edition="sp3"/>
        <vers num="7.0" edition="sp3:express"/>
        <vers num="7.0" edition="sp4"/>
        <vers num="7.0" edition="sp4:express"/>
        <vers num="7.0" edition="sp5"/>
        <vers num="7.0" edition="sp5:express"/>
        <vers num="7.0" edition="sp6"/>
        <vers num="7.0" edition="sp6:express"/>
        <vers num="8.1" edition="sp1"/>
        <vers num="8.1" edition="sp1:express"/>
        <vers num="8.1" edition="sp2"/>
        <vers num="8.1" edition="sp2:express"/>
        <vers num="8.1" edition="sp3"/>
        <vers num="8.1" edition="sp3:express"/>
        <vers num="8.1" edition="sp4"/>
        <vers num="8.1" edition="sp4:express"/>
        <vers num="8.1" edition="sp5"/>
        <vers num="8.1" edition="sp5:express"/>
        <vers num="9.0" edition=""/>
        <vers num="9.0" edition=":express"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0420" published="2006-01-25" name="CVE-2006-0420" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">BEA WebLogic Server and WebLogic Express 8.1 through SP4 and 7.0 through SP6 does not properly handle when servlets use relative forwarding, which allows remote attackers to cause a denial of service (slowdown) via unknown attack vectors that cause "looping stack overflow errors."</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1015528" source="SECTRACK" patch="1">1015528</ref>
      <ref url="http://dev2dev.bea.com/pub/advisory/164" source="BEA" patch="1" adv="1">BEA06-106.01</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="7.0" edition="sp1"/>
        <vers num="7.0" edition="sp1:express"/>
        <vers num="7.0" edition="sp2"/>
        <vers num="7.0" edition="sp2:express"/>
        <vers num="7.0" edition="sp3"/>
        <vers num="7.0" edition="sp3:express"/>
        <vers num="7.0" edition="sp4"/>
        <vers num="7.0" edition="sp4:express"/>
        <vers num="7.0" edition="sp5"/>
        <vers num="7.0" edition="sp5:express"/>
        <vers num="7.0" edition="sp6"/>
        <vers num="7.0" edition="sp6:express"/>
        <vers num="8.1" edition="sp1"/>
        <vers num="8.1" edition="sp1:express"/>
        <vers num="8.1" edition="sp2"/>
        <vers num="8.1" edition="sp2:express"/>
        <vers num="8.1" edition="sp3"/>
        <vers num="8.1" edition="sp3:express"/>
        <vers num="8.1" edition="sp4"/>
        <vers num="8.1" edition="sp4:express"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0421" published="2006-01-25" name="CVE-2006-0421" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">By design, BEA WebLogic Server and WebLogic Express 7.0 and 6.1, when creating multiple domains from the same WebLogic instance on the same machine, allows administrators of any created domain to access other created domains, which could allow administrators to gain privileges that were not intended.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1015528" source="SECTRACK" patch="1">1015528</ref>
      <ref url="http://secunia.com/advisories/18581" source="SECUNIA" patch="1" adv="1">18581</ref>
      <ref url="http://dev2dev.bea.com/pub/advisory/165" source="BEA" patch="1" adv="1">BEA06-108.00</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24286" source="XF">weblogic-cross-domain-management(24286)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0313" source="VUPEN">ADV-2006-0313</ref>
      <ref url="http://www.securityfocus.com/bid/16358" source="BID">16358</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="6.1" edition=""/>
        <vers num="6.1" edition=":express"/>
        <vers num="7.0" edition=""/>
        <vers num="7.0" edition=":express"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0422" published="2006-01-25" name="CVE-2006-0422" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in BEA WebLogic Server and WebLogic Express 8.1 through SP4, 7.0 through SP6, and 6.1 through SP7 allow remote attackers to access MBean attributes or cause an unspecified denial of service via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1015528" source="SECTRACK" patch="1">1015528</ref>
      <ref url="http://secunia.com/advisories/18592" source="SECUNIA" patch="1" adv="1">18592</ref>
      <ref url="http://dev2dev.bea.com/pub/advisory/166" source="BEA" patch="1" adv="1">BEA06-109.00</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24294" source="XF">weblogic-java-mbean-access(24294)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0313" source="VUPEN">ADV-2006-0313</ref>
      <ref url="http://www.securityfocus.com/bid/16358" source="BID">16358</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="6.1" edition="sp1"/>
        <vers num="6.1" edition="sp1:express"/>
        <vers num="6.1" edition="sp2"/>
        <vers num="6.1" edition="sp2:express"/>
        <vers num="6.1" edition="sp3"/>
        <vers num="6.1" edition="sp3:express"/>
        <vers num="6.1" edition="sp4"/>
        <vers num="6.1" edition="sp4:express"/>
        <vers num="6.1" edition="sp5"/>
        <vers num="6.1" edition="sp5:express"/>
        <vers num="6.1" edition="sp6"/>
        <vers num="6.1" edition="sp7"/>
        <vers num="6.1" edition="sp7:express"/>
        <vers num="7.0" edition="sp1"/>
        <vers num="7.0" edition="sp1:express"/>
        <vers num="7.0" edition="sp2"/>
        <vers num="7.0" edition="sp2:express"/>
        <vers num="7.0" edition="sp3"/>
        <vers num="7.0" edition="sp3:express"/>
        <vers num="7.0" edition="sp4"/>
        <vers num="7.0" edition="sp4:express"/>
        <vers num="7.0" edition="sp5"/>
        <vers num="7.0" edition="sp5:express"/>
        <vers num="7.0" edition="sp6"/>
        <vers num="7.0" edition="sp6:express"/>
        <vers num="8.1" edition="sp1"/>
        <vers num="8.1" edition="sp1:express"/>
        <vers num="8.1" edition="sp2"/>
        <vers num="8.1" edition="sp2:express"/>
        <vers num="8.1" edition="sp3"/>
        <vers num="8.1" edition="sp3:express"/>
        <vers num="8.1" edition="sp4"/>
        <vers num="8.1" edition="sp4:express"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0423" published="2006-01-25" name="CVE-2006-0423" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">BEA WebLogic Portal 8.1 through SP3 stores the password for the RDBMS Authentication provider in cleartext in the config.xml file, which allows attackers to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1015528" source="SECTRACK" patch="1">1015528</ref>
      <ref url="http://dev2dev.bea.com/pub/advisory/167" source="BEA" patch="1" adv="1">BEA06-110.00</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/40705" source="XF">weblogic-portal-config-info-disclosure(40705)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24284" source="XF">weblogicportal-config-info-disclosure(24284)</ref>
      <ref url="http://www.vupen.com/english/advisories/2008/0613" source="VUPEN">ADV-2008-0613</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0312" source="VUPEN">ADV-2006-0312</ref>
      <ref url="http://www.securityfocus.com/bid/16358" source="BID">16358</ref>
      <ref url="http://secunia.com/advisories/18593" source="SECUNIA">18593</ref>
      <ref url="http://dev2dev.bea.com/pub/advisory/262" source="BEA">BEA08-110.01</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_portal">
        <vers num="8.1" edition="sp1"/>
        <vers num="8.1" edition="sp2"/>
        <vers num="8.1" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0424" published="2006-01-25" name="CVE-2006-0424" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">BEA WebLogic Server and WebLogic Express 8.1 through SP4, 7.0 through SP6, and 6.1 through SP7 allows remote authenticated guest users to read the server log and obtain sensitive configuration information.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1015528" source="SECTRACK" patch="1">1015528</ref>
      <ref url="http://secunia.com/advisories/18592" source="SECUNIA" patch="1" adv="1">18592</ref>
      <ref url="http://dev2dev.bea.com/pub/advisory/168" source="BEA" patch="1" adv="1">BEA06-111.00</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24295" source="XF">weblogic-server-log-disclosure(24295)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0313" source="VUPEN">ADV-2006-0313</ref>
      <ref url="http://www.securityfocus.com/bid/16358" source="BID">16358</ref>
      <ref url="http://www.osvdb.org/22776" source="OSVDB">22776</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="6.1" edition="sp1"/>
        <vers num="6.1" edition="sp1:express"/>
        <vers num="6.1" edition="sp2"/>
        <vers num="6.1" edition="sp2:express"/>
        <vers num="6.1" edition="sp3"/>
        <vers num="6.1" edition="sp3:express"/>
        <vers num="6.1" edition="sp4"/>
        <vers num="6.1" edition="sp4:express"/>
        <vers num="6.1" edition="sp5"/>
        <vers num="6.1" edition="sp5:express"/>
        <vers num="6.1" edition="sp6"/>
        <vers num="6.1" edition="sp7"/>
        <vers num="6.1" edition="sp7:express"/>
        <vers num="7.0" edition="sp1"/>
        <vers num="7.0" edition="sp1:express"/>
        <vers num="7.0" edition="sp2"/>
        <vers num="7.0" edition="sp2:express"/>
        <vers num="7.0" edition="sp3"/>
        <vers num="7.0" edition="sp3:express"/>
        <vers num="7.0" edition="sp4"/>
        <vers num="7.0" edition="sp4:express"/>
        <vers num="7.0" edition="sp5"/>
        <vers num="7.0" edition="sp5:express"/>
        <vers num="7.0" edition="sp6"/>
        <vers num="7.0" edition="sp6:express"/>
        <vers num="8.1" edition="sp1"/>
        <vers num="8.1" edition="sp1:express"/>
        <vers num="8.1" edition="sp2"/>
        <vers num="8.1" edition="sp2:express"/>
        <vers num="8.1" edition="sp3"/>
        <vers num="8.1" edition="sp3:express"/>
        <vers num="8.1" edition="sp4"/>
        <vers num="8.1" edition="sp4:express"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0425" published="2006-01-25" name="CVE-2006-0425" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">BEA WebLogic Portal 8.1 through SP4 allows remote attackers to obtain the source for a deployment descriptor file via unknown vectors.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1015528" source="SECTRACK" patch="1">1015528</ref>
      <ref url="http://dev2dev.bea.com/pub/advisory/169" source="BEA" patch="1" adv="1">BEA06-112.00</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24297" source="XF">weblogic-deployment-descriptor-disclosure(24297)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0312" source="VUPEN">ADV-2006-0312</ref>
      <ref url="http://www.securityfocus.com/bid/16358" source="BID">16358</ref>
      <ref url="http://secunia.com/advisories/18593" source="SECUNIA">18593</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_portal">
        <vers num="8.1" edition="sp1"/>
        <vers num="8.1" edition="sp2"/>
        <vers num="8.1" edition="sp3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0426" published="2006-01-25" name="CVE-2006-0426" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">BEA WebLogic Server and WebLogic Express 8.1 through SP4, when configuration auditing is enabled and a password change occurs, stores the old and new passwords in cleartext in the DefaultAuditRecorder.log file, which could allow attackers to gain privileges.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1015528" source="SECTRACK" patch="1">1015528</ref>
      <ref url="http://secunia.com/advisories/18592" source="SECUNIA" patch="1" adv="1">18592</ref>
      <ref url="http://dev2dev.bea.com/pub/advisory/170" source="BEA" patch="1" adv="1">BEA06-113.00</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24290" source="XF">weblogic-password-information-disclosure(24290)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0313" source="VUPEN">ADV-2006-0313</ref>
      <ref url="http://www.securityfocus.com/bid/16358" source="BID">16358</ref>
      <ref url="http://www.osvdb.org/22775" source="OSVDB">22775</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="8.1" edition="sp1"/>
        <vers num="8.1" edition="sp1:express"/>
        <vers num="8.1" edition="sp2"/>
        <vers num="8.1" edition="sp2:express"/>
        <vers num="8.1" edition="sp3"/>
        <vers num="8.1" edition="sp3:express"/>
        <vers num="8.1" edition="sp4"/>
        <vers num="8.1" edition="sp4:express"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0427" published="2006-01-25" name="CVE-2006-0427" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in BEA WebLogic Server and WebLogic Express 9.0 and 8.1 through SP5 allows malicious EJBs or servlet applications to decrypt system passwords, possibly by accessing functionality that should have been restricted.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1015528" source="SECTRACK" patch="1">1015528</ref>
      <ref url="http://secunia.com/advisories/18592" source="SECUNIA" patch="1" adv="1">18592</ref>
      <ref url="http://dev2dev.bea.com/pub/advisory/171" source="BEA" patch="1" adv="1">BEA06-114.00</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24291" source="XF">weblogic-servlets-obtain-information(24291)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0313" source="VUPEN">ADV-2006-0313</ref>
      <ref url="http://www.securityfocus.com/bid/16358" source="BID">16358</ref>
      <ref url="http://www.osvdb.org/22774" source="OSVDB">22774</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="8.1" edition="sp1"/>
        <vers num="8.1" edition="sp1:express"/>
        <vers num="8.1" edition="sp2"/>
        <vers num="8.1" edition="sp2:express"/>
        <vers num="8.1" edition="sp3"/>
        <vers num="8.1" edition="sp3:express"/>
        <vers num="8.1" edition="sp4"/>
        <vers num="8.1" edition="sp4:express"/>
        <vers num="8.1" edition="sp5"/>
        <vers num="8.1" edition="sp5:express"/>
        <vers num="9.0" edition="sp1"/>
        <vers num="9.0" edition="sp1:express"/>
        <vers num="9.0" edition="sp2"/>
        <vers num="9.0" edition="sp2:express"/>
        <vers num="9.0" edition="sp3"/>
        <vers num="9.0" edition="sp3:express"/>
        <vers num="9.0" edition="sp4"/>
        <vers num="9.0" edition="sp4:express"/>
        <vers num="9.0" edition="sp5"/>
        <vers num="9.0" edition="sp5:express"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0428" published="2006-01-25" name="CVE-2006-0428" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in BEA WebLogic Portal 8.1 SP3 through SP5, when using Web Services Remote Portlets (WSRP), allows remote attackers to access restricted web resources via crafted URLs.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1015528" source="SECTRACK" patch="1">1015528</ref>
      <ref url="http://dev2dev.bea.com/pub/advisory/172" source="BEA" patch="1" adv="1">BEA06-115.00</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24293" source="XF">weblogic-wsrp-gain-access(24293)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0312" source="VUPEN">ADV-2006-0312</ref>
      <ref url="http://www.securityfocus.com/bid/16358" source="BID">16358</ref>
      <ref url="http://www.osvdb.org/22767" source="OSVDB">22767</ref>
      <ref url="http://secunia.com/advisories/18593" source="SECUNIA">18593</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_portal">
        <vers num="8.1" edition="sp3"/>
        <vers num="8.1" edition="sp4"/>
        <vers num="8.1" edition="sp5"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0429" published="2006-01-25" name="CVE-2006-0429" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">BEA WebLogic Server and WebLogic Express 9.0 causes new security providers to appear active even if they have not been activated by a server reboot, which could cause an administrator to perform inappropriate, security-relevant actions.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1015528" source="SECTRACK" patch="1">1015528</ref>
      <ref url="http://secunia.com/advisories/18592" source="SECUNIA" patch="1" adv="1">18592</ref>
      <ref url="http://dev2dev.bea.com/pub/advisory/173" source="BEA" patch="1" adv="1">BEA06-116.00</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24298" source="XF">weblogic-security-provider-weakness(24298)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0313" source="VUPEN">ADV-2006-0313</ref>
      <ref url="http://www.securityfocus.com/bid/16358" source="BID">16358</ref>
      <ref url="http://www.osvdb.org/22773" source="OSVDB">22773</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="9.0" edition=""/>
        <vers num="9.0" edition=":express"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0430" published="2006-01-25" name="CVE-2006-0430" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Certain configurations of BEA WebLogic Server and WebLogic Express 9.0, 8.1 through SP5, and 7.0 through SP6, when connection filters are enabled, cause the server to run more slowly, which makes it easier for remote attackers to cause a denial of service (server slowdown).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <config/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1015528" source="SECTRACK" patch="1">1015528</ref>
      <ref url="http://secunia.com/advisories/18592" source="SECUNIA" patch="1" adv="1">18592</ref>
      <ref url="http://dev2dev.bea.com/pub/advisory/174" source="BEA" patch="1" adv="1">BEA06-117.00</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0313" source="VUPEN">ADV-2006-0313</ref>
      <ref url="http://www.securityfocus.com/bid/16358" source="BID">16358</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24301" source="XF">weblogic-connection-filter-dos(24301)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="7.0" edition="sp1"/>
        <vers num="7.0" edition="sp1:express"/>
        <vers num="7.0" edition="sp2"/>
        <vers num="7.0" edition="sp2:express"/>
        <vers num="7.0" edition="sp3"/>
        <vers num="7.0" edition="sp3:express"/>
        <vers num="7.0" edition="sp4"/>
        <vers num="7.0" edition="sp4:express"/>
        <vers num="7.0" edition="sp5"/>
        <vers num="7.0" edition="sp5:express"/>
        <vers num="7.0" edition="sp6"/>
        <vers num="7.0" edition="sp6:express"/>
        <vers num="8.1" edition="sp1"/>
        <vers num="8.1" edition="sp1:express"/>
        <vers num="8.1" edition="sp2"/>
        <vers num="8.1" edition="sp2:express"/>
        <vers num="8.1" edition="sp3"/>
        <vers num="8.1" edition="sp3:express"/>
        <vers num="8.1" edition="sp4"/>
        <vers num="8.1" edition="sp4:express"/>
        <vers num="9.0" edition="sp1"/>
        <vers num="9.0" edition="sp1:express"/>
        <vers num="9.0" edition="sp2"/>
        <vers num="9.0" edition="sp2:express"/>
        <vers num="9.0" edition="sp3"/>
        <vers num="9.0" edition="sp3:express"/>
        <vers num="9.0" edition="sp4"/>
        <vers num="9.0" edition="sp4:express"/>
        <vers num="9.0" edition="sp5"/>
        <vers num="9.0" edition="sp5:express"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0431" published="2006-01-25" name="CVE-2006-0431" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in BEA WebLogic Server and WebLogic Express 8.1 SP5 allows untrusted applications to obtain the server's SSL identity via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1015528" source="SECTRACK" patch="1">1015528</ref>
      <ref url="http://secunia.com/advisories/18592" source="SECUNIA" patch="1" adv="1">18592</ref>
      <ref url="http://dev2dev.bea.com/pub/advisory/175" source="BEA" patch="1" adv="1">BEA06-118.00</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0313" source="VUPEN">ADV-2006-0313</ref>
      <ref url="http://www.securityfocus.com/bid/16358" source="BID">16358</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24302" source="XF">weblogic-ssl-identity-exposure(24302)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="8.1" edition="sp5"/>
        <vers num="8.1" edition="sp5:express"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0432" published="2006-01-25" name="CVE-2006-0432" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in BEA WebLogic Server and WebLogic Express 9.0, when an Administrator uses the WebLogic Administration Console to add custom security policies, causes incorrect policies to be created, which prevents the server from properly protecting JNDI resources.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1015528" source="SECTRACK" patch="1">1015528</ref>
      <ref url="http://secunia.com/advisories/18592" source="SECUNIA" patch="1" adv="1">18592</ref>
      <ref url="http://dev2dev.bea.com/pub/advisory/176" source="BEA" patch="1" adv="1">BEA06-119.00</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24299" source="XF">weblogic-jdni-security-weakness(24299)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0313" source="VUPEN">ADV-2006-0313</ref>
      <ref url="http://www.securityfocus.com/bid/16358" source="BID">16358</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bea" name="weblogic_server">
        <vers num="9.0" edition=""/>
        <vers num="9.0" edition=":express"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0433" published="2006-02-02" name="CVE-2006-0433" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Selective Acknowledgement (SACK) in FreeBSD 5.3 and 5.4 does not properly handle an incoming selective acknowledgement when there is insufficient memory, which might allow remote attackers to cause a denial of service (infinite loop).</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.osvdb.org/22861" source="OSVDB" patch="1">22861</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0409" source="VUPEN">ADV-2006-0409</ref>
      <ref url="http://www.securityfocus.com/bid/16466" source="BID">16466</ref>
      <ref url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:08.sack.asc" source="FREEBSD">FreeBSD-SA-06:08</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24453" source="XF">bsd-sack-handling-dos(24453)</ref>
      <ref url="http://securitytracker.com/id?1015566" source="SECTRACK">1015566</ref>
      <ref url="http://securityreason.com/securityalert/399" source="SREASON">399</ref>
      <ref url="http://secunia.com/advisories/18696" source="SECUNIA">18696</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="5.3"/>
        <vers num="5.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0434" published="2006-01-26" name="CVE-2006-0434" modified="2013-01-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in action.php in phpXplorer allows remote attackers to read arbitrary files via ".." (dot dot) sequences and null bytes in the sAction parameter, a different vulnerability than CVE-2006-0244.  NOTE: if the functionality of phpXplorer supports the upload of PHP files, then this issue would not cross privilege boundaries and would not be a vulnerability.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/39982" source="XF">phpxplorer-sshare-directory-traversal(39982)</ref>
      <ref url="http://www.securityfocus.com/bid/16292" source="BID">16292</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/422434/100/0/threaded" source="BUGTRAQ">20060118 phpXplorer file inclusion biyosecurity.be</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpxplorer" name="phpxplorer">
        <vers num="-"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0435" published="2006-01-26" name="CVE-2006-0435" modified="2012-10-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle PL/SQL (PLSQL), as used in Database Server DS 9.2.0.7 and 10.1.0.5, Application Server 1.0.2.2, 9.0.4.2, 10.1.2.0.2, 10.1.2.1.0, and 10.1.3.0.0, E-Business Suite and Applications 11.5.10, and Collaboration Suite 10.1.1, 10.1.2.0, 10.1.2.1, and 9.0.4.2, allows attackers to bypass the PLSQLExclusion list and access excluded packages and procedures, aka Vuln# PLSQL01.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/169164" source="CERT-VN">VU#169164</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423029/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20060125 Workaround for unpatched Oracle PLSQL Gateway flaw</ref>
      <ref url="http://securitytracker.com/id?1015961" source="SECTRACK" patch="1">1015961</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24363" source="XF">oracle-plsql-command-execution(24363)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1571" source="VUPEN" adv="1">ADV-2006-1571</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/1397" source="VUPEN" adv="1">ADV-2006-1397</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0338" source="VUPEN" adv="1">ADV-2006-0338</ref>
      <ref url="http://www.securityfocus.com/bid/16384" source="BID">16384</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded" source="HP">HPSBMA02113</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/432267/100/0/threaded" source="HP">HPSBMA02113</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/424394/100/0/threaded" source="BUGTRAQ">20060208 Re: Workaround for unpatched Oracle PLSQL Gateway flaw</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423822/100/0/threaded" source="BUGTRAQ">20060202 More on the workaround for the unpatched Oracle PLSQL Gateway flaw</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423819/100/0/threaded" source="BUGTRAQ">20060202 The History of the Oracle PLSQL Gateway Flaw</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423673/100/0/threaded" source="BUGTRAQ">20060131 Re: Workaround for unpatched Oracle PLSQL Gateway flaw</ref>
      <ref url="http://www.osvdb.org/22719" source="OSVDB">22719</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/pdf/public_vuln_to_advisory_mapping.html" source="MISC">http://www.oracle.com/technology/deploy/security/pdf/public_vuln_to_advisory_mapping.html</ref>
      <ref url="http://www.oracle.com/technetwork/topics/security/cpuapr2006-090826.html" source="CONFIRM">http://www.oracle.com/technetwork/topics/security/cpuapr2006-090826.html</ref>
      <ref url="http://securitytracker.com/id?1015544" source="SECTRACK">1015544</ref>
      <ref url="http://securityreason.com/securityalert/403" source="SREASON">403</ref>
      <ref url="http://securityreason.com/securityalert/402" source="SREASON">402</ref>
      <ref url="http://secunia.com/advisories/19859" source="SECUNIA" adv="1">19859</ref>
      <ref url="http://secunia.com/advisories/19712" source="SECUNIA" adv="1">19712</ref>
      <ref url="http://secunia.com/advisories/18621" source="SECUNIA">18621</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041742.html" source="FULLDISC">20060125 Workaround for unpatched Oracle PLSQL Gateway flaw</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-February/041899.html" source="FULLDISC">20060202 More on the workaround for the unpatched Oracle PLSQL Gateway flaw</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-February/041898.html" source="FULLDISC">20060202 The History of the Oracle PLSQL Gateway Flaw</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="1.0.2"/>
        <vers num="1.0.2.0"/>
        <vers num="1.0.2.1"/>
        <vers num="1.0.2.1s"/>
        <vers num="1.0.2.2"/>
        <vers num="1.0.2.2.2"/>
        <vers num="10.1.0.2"/>
        <vers num="10.1.0.3"/>
        <vers num="10.1.0.3.1"/>
        <vers num="10.1.0.4"/>
        <vers num="10.1.2"/>
        <vers num="10.1.2.0.2"/>
        <vers num="10.1.2.1.0"/>
        <vers num="10.1.2_.0.1"/>
        <vers num="9.0.2"/>
        <vers num="9.0.2.0.0"/>
        <vers num="9.0.2.0.1"/>
        <vers num="9.0.2.1"/>
        <vers num="9.0.2.2"/>
        <vers num="9.0.2.3"/>
        <vers num="9.0.3"/>
        <vers num="9.0.3.1"/>
        <vers num="9.0.4.0"/>
        <vers num="9.0.4.1"/>
        <vers num="9.0.4.2"/>
        <vers num="9.2.0.6"/>
        <vers num="9.2.0.7"/>
      </prod>
      <prod vendor="oracle" name="http_server">
        <vers num="1.0.2.0"/>
        <vers num="1.0.2.1"/>
        <vers num="1.0.2.1s_for_apps"/>
        <vers num="1.0.2.2"/>
        <vers num="1.0.2.2_roll_up_2"/>
        <vers num="8.1.7"/>
        <vers num="9.0.1"/>
        <vers num="9.0.2"/>
        <vers num="9.0.2.3"/>
        <vers num="9.0.3.1"/>
        <vers num="9.1"/>
        <vers num="9.2.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0436" published="2006-01-26" name="CVE-2006-0436" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unspecified vulnerability in HP HP-UX B.11.00, B.11.04, and B.11.11 allows local users to gain privileges via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1015530" source="SECTRACK" patch="1">1015530</ref>
      <ref url="http://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00591401" source="HP">HPSBUX02091</ref>
      <ref url="http://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00591401" source="HP">SSRT061099</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0322" source="VUPEN">ADV-2006-0322</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24318" source="XF">hpux-unspecified-privilege-escalation(24318)</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-025.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-025.htm</ref>
      <ref url="http://secunia.com/advisories/18600" source="SECUNIA">18600</ref>
      <ref url="http://secunia.com/advisories/18596" source="SECUNIA">18596</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1586" source="OVAL" sig="1">oval:org.mitre.oval:def:1586</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1577" source="OVAL" sig="1">oval:org.mitre.oval:def:1577</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1453" source="OVAL" sig="1">oval:org.mitre.oval:def:1453</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="11.00"/>
        <vers num="11.11"/>
        <vers num="11.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0437" published="2006-02-06" name="CVE-2006-0437" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in admin_smilies.php in phpBB 2.0.19 allows remote attackers to inject arbitrary web script or HTML via Javascript events such as "onmouseover" in the (1) smile_url or (2) smile_emotion parameters, which bypasses a check for "&lt;" and ">" characters.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24497" source="XF">phpbb-referer-header-http-xss(24497)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0445" source="VUPEN">ADV-2006-0445</ref>
      <ref url="http://www.osvdb.org/22928" source="OSVDB">22928</ref>
      <ref url="http://securityreason.com/achievement_securityalert/31" source="SREASONRES">20060203 phpBB 2.0.19 Cross Site Request Forgeries and XSS Admin</ref>
      <ref url="http://secunia.com/advisories/18693" source="SECUNIA" adv="1">18693</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-February/041920.html" source="FULLDISC">20060203 phpBB 2.0.19 Cross Site Request Forgeries and XSS Admin</ref>
      <ref url="http://securityreason.com/securityalert/406" source="SREASON">406</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb_group" name="phpbb">
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.12"/>
        <vers num="2.0.13"/>
        <vers num="2.0.14"/>
        <vers num="2.0.15"/>
        <vers num="2.0.16"/>
        <vers num="2.0.17"/>
        <vers num="2.0.18"/>
        <vers num="2.0.19"/>
        <vers num="2.0.6c"/>
        <vers num="2.0.6d"/>
        <vers num="2.0.7"/>
        <vers num="2.0.7a"/>
        <vers num="2.0.8"/>
        <vers num="2.0.8a"/>
        <vers num="2.0.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0438" published="2006-02-06" name="CVE-2006-0438" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in phpBB 2.0.19, when Link to off-site Avatar or bbcode (IMG) are enabled, allows remote attackers to perform unauthorized actions as a logged in user via a link or IMG tag in a user profile, as demonstrated using links to (1) admin/admin_users.php and (2) modcp.php.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0445" source="VUPEN">ADV-2006-0445</ref>
      <ref url="http://securityreason.com/achievement_securityalert/31" source="SREASONRES">20060203 phpBB 2.0.19 Cross Site Request Forgeries and XSS Admin</ref>
      <ref url="http://secunia.com/advisories/18693" source="SECUNIA" adv="1">18693</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24497" source="XF">phpbb-referer-header-http-xss(24497)</ref>
      <ref url="http://www.osvdb.org/22929" source="OSVDB">22929</ref>
      <ref url="http://securityreason.com/securityalert/406" source="SREASON">406</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-February/041920.html" source="FULLDISC">20060203 phpBB 2.0.19 Cross Site Request Forgeries and XSS Admin</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb_group" name="phpbb">
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.12"/>
        <vers num="2.0.13"/>
        <vers num="2.0.14"/>
        <vers num="2.0.15"/>
        <vers num="2.0.16"/>
        <vers num="2.0.17"/>
        <vers num="2.0.18"/>
        <vers num="2.0.19"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.6c"/>
        <vers num="2.0.6d"/>
        <vers num="2.0.7"/>
        <vers num="2.0.7a"/>
        <vers num="2.0.8"/>
        <vers num="2.0.8a"/>
        <vers num="2.0.9"/>
        <vers num="2.0_beta1"/>
        <vers num="2.0_rc1"/>
        <vers num="2.0_rc2"/>
        <vers num="2.0_rc3"/>
        <vers num="2.0_rc4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0439" published="2006-01-26" name="CVE-2006-0439" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Text Rider 2.4 stores sensitive data in the data directory under the web document root with insufficient access control, which allows remote attackers to obtain usernames and password hashes by directly accessing data/userlist.txt.</descript>
    </desc>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24279" source="XF">textrider-data-information-disclosure(24279)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0321" source="VUPEN">ADV-2006-0321</ref>
      <ref url="http://secunia.com/advisories/18605" source="SECUNIA" adv="1">18605</ref>
      <ref url="http://evuln.com/vulns/46/summary.html" source="MISC" adv="1">http://evuln.com/vulns/46/summary.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423130/100/0/threaded" source="BUGTRAQ">20060124 [eVuln] Text Rider Sensitive Information Disclosure</ref>
      <ref url="http://securitytracker.com/id?1015533" source="SECTRACK">1015533</ref>
    </refs>
    <vuln_soft>
      <prod vendor="text_rider" name="text_rider">
        <vers num="2.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0440" published="2006-01-26" name="CVE-2006-0440" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Text Rider 2.4 allows attackers to bypass authentication and upload files without providing a valid password by obtaining the MD5 hash of the password (possibly via another vulnerability that reads it from a data file), then including the hash in a cookie.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <access/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://evuln.com/vulns/46/summary.html" source="MISC" adv="1">http://evuln.com/vulns/46/summary.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423130/100/0/threaded" source="BUGTRAQ">20060124 [eVuln] Text Rider Sensitive Information Disclosure</ref>
      <ref url="http://securitytracker.com/id?1015533" source="SECTRACK">1015533</ref>
    </refs>
    <vuln_soft>
      <prod vendor="text_rider" name="text_rider">
        <vers num="2.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0441" published="2006-01-26" name="CVE-2006-0441" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Sami FTP Server 2.0.1 allows remote attackers to execute arbitrary code via a long USER command, which triggers the overflow when the log is viewed.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0317" source="VUPEN">ADV-2006-0317</ref>
      <ref url="http://www.securityfocus.com/bid/16370" source="BID">16370</ref>
      <ref url="http://www.critical.lt/?vulnerabilities/208" source="MISC" adv="1">http://www.critical.lt/?vulnerabilities/208</ref>
      <ref url="http://secunia.com/advisories/18574" source="SECUNIA" adv="1">18574</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24325" source="XF">samiftpserver-user-bo(24325)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423148/100/0/threaded" source="BUGTRAQ">20060124 SamiFTPd buffer overflow</ref>
      <ref url="http://www.karjasoft.com/samiftp/news" source="CONFIRM">http://www.karjasoft.com/samiftp/news</ref>
      <ref url="http://downloads.securityfocus.com/vulnerabilities/exploits/sami_ftp_poc.pl" source="MISC">http://downloads.securityfocus.com/vulnerabilities/exploits/sami_ftp_poc.pl</ref>
    </refs>
    <vuln_soft>
      <prod vendor="karjasoft" name="sami_ftp_server">
        <vers num="2.0.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0442" published="2006-01-26" name="CVE-2006-0442" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in usercp.php in MyBulletinBoard (MyBB) 1.02 allow remote attackers to inject arbitrary web script or HTML via the (1) notepad parameter in a notepad action and (2) signature parameter in a editsig action.  NOTE: These are different attack vectors, and probably a different vulnerability, than CVE-2006-0218 and CVE-2006-0219.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0316" source="VUPEN">ADV-2006-0316</ref>
      <ref url="http://www.securityfocus.com/bid/16361" source="BID">16361</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423128/100/0/threaded" source="BUGTRAQ">20060124 [KAPDA::#25] - MyBB 1.x Cross_Site_Scripting</ref>
      <ref url="http://securitytracker.com/id?1015535" source="SECTRACK">1015535</ref>
      <ref url="http://secunia.com/advisories/18603" source="SECUNIA" adv="1">18603</ref>
      <ref url="http://kapda.ir/advisory-241.html" source="MISC" adv="1">http://kapda.ir/advisory-241.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mybulletinboard" name="mybulletinboard">
        <vers num="1.0.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0443" published="2006-01-26" name="CVE-2006-0443" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in archive.php in CheesyBlog 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) realname and (2) comment parameters, or (3) via a javascript URI in the url parameter, when adding a comment.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0326" source="VUPEN">ADV-2006-0326</ref>
      <ref url="http://www.securityfocus.com/bid/16376" source="BID">16376</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423023/100/0/threaded" source="BUGTRAQ" adv="1">20060125 [eVuln] CheesyBlog XSS Vulnerability</ref>
      <ref url="http://evuln.com/vulns/49/summary.html" source="MISC" adv="1">http://evuln.com/vulns/49/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24292" source="XF">cheesyblog-archive-xss(24292)</ref>
      <ref url="http://www.osvdb.org/22716" source="OSVDB">22716</ref>
      <ref url="http://securityreason.com/securityalert/369" source="SREASON">369</ref>
      <ref url="http://secunia.com/advisories/18610" source="SECUNIA">18610</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cheesyblog" name="cheesyblog">
        <vers num="1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0444" published="2006-01-26" name="CVE-2006-0444" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in Phpclanwebsite (aka PCW) 1.23.1 allows remote attackers to execute arbitrary SQL commands via the (1) par parameter in the post function on the forum page and possibly the (2) poll_id parameter on the poll page.  NOTE: the poll_id vector can also allow resultant cross-site scripting (XSS) from an unquoted error message for invalid SQL syntax.</descript>
    </desc>
    <sols>
      <sol source="nvd">A simple fix has been released on the Main PCW site available directly at &lt;a href="http://www.phpclanwebsite.com/index.php?page=downloads&amp;func=browselist&amp;par=1">http://www.phpclanwebsite.com/index.php?page=downloads&amp;func=browselist&amp;par=1&lt;/a>
Please download and install imediately.
Tech note: Filters id number (par) to contain numbers only.
</sol>
    </sols>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16391" source="BID" patch="1">16391</ref>
      <ref url="http://secunia.com/advisories/18597" source="SECUNIA" patch="1" adv="1">18597</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0342" source="VUPEN">ADV-2006-0342</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423145/100/0/threaded" source="BUGTRAQ" adv="1">20060125 HYSA-2006-002 Phpclanwebsite 1.23.1 Multiple Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/22722" source="OSVDB">22722</ref>
      <ref url="http://www.osvdb.org/22720" source="OSVDB">22720</ref>
      <ref url="http://www.h4cky0u.org/advisories/HYSA-2006-002-phpclan.txt" source="MISC" adv="1">http://www.h4cky0u.org/advisories/HYSA-2006-002-phpclan.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24355" source="XF">phpclanwebsite-index-sql-injection(24355)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpclanwebsite" name="phpclanwebsite">
        <vers num="1.23.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0445" published="2006-01-26" name="CVE-2006-0445" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">index.php in Phpclanwebsite 1.23.1 allows remote authenticated users to obtain the installation path by specifying an invalid file name to the uploader page, as demonstrated by "\", which will display the full path of uploader.php.  NOTE: this might be the result of a file inclusion vulnerability.</descript>
    </desc>
    <sols>
      <sol source="nvd">Please add the following to the config.php file to avoid all such exploits.

ini_set('display_errors', false);
</sol>
    </sols>
    <loss_types>
      <conf/>
    </loss_types>
    <vuln_types>
      <input/>
      <design/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16391" source="BID">16391</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423145/100/0/threaded" source="BUGTRAQ" adv="1">20060125 HYSA-2006-002 Phpclanwebsite 1.23.1 Multiple Vulnerabilities</ref>
      <ref url="http://www.osvdb.org/22721" source="OSVDB">22721</ref>
      <ref url="http://www.h4cky0u.org/advisories/HYSA-2006-002-phpclan.txt" source="MISC" adv="1">http://www.h4cky0u.org/advisories/HYSA-2006-002-phpclan.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpclanwebsite" name="phpclanwebsite">
        <vers num="1.23.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0446" published="2006-01-26" name="CVE-2006-0446" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in WeBWorK 2.1.3 and 2.2-pre1 allows remote privilged attackers to execute arbitrary commands as the web server via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18594" source="SECUNIA" patch="1" adv="1">18594</ref>
      <ref url="http://devel.webwork.rochester.edu/twiki/bin/view/Webwork/WeBWorKRelease2pt1pt4" source="CONFIRM" patch="1">http://devel.webwork.rochester.edu/twiki/bin/view/Webwork/WeBWorKRelease2pt1pt4</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0319" source="VUPEN">ADV-2006-0319</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24322" source="XF">webwork-unknown-command-execution(24322)</ref>
      <ref url="http://www.securityfocus.com/bid/16371" source="BID">16371</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webwork" name="webwork">
        <vers num="2.1.3"/>
        <vers num="2.2-pre1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0447" published="2006-01-26" name="CVE-2006-0447" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in E-Post Mail Server 4.10 and SPA-PRO Mail @Solomon 4.00 allow remote attackers to execute arbitrary code via a long username to the (1) AUTH PLAIN or (2) AUTH LOGIN SMTP commands, which is not properly handled by (a) EPSTRS.EXE or (b) SPA-RS.EXE; (3) a long username in the APOP POP3 command, which is not properly handled by (c) EPSTPOP4S.EXE or (d) SPA-POP3S.EXE; (4) a long IMAP DELETE command, which is not properly handled by (e) EPSTIMAP4S.EXE or (f) SPA-IMAP4S.EXE.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/secunia_research/2006-1/advisory/" source="MISC" patch="1" adv="1">http://secunia.com/secunia_research/2006-1/advisory/</ref>
      <ref url="http://secunia.com/advisories/18480" source="SECUNIA" patch="1" adv="1">18480</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0318" source="VUPEN">ADV-2006-0318</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24334" source="XF">epost-imap-mailbox-dos(24334)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24333" source="XF">epost-pop3-username-bo(24333)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24331" source="XF">epost-smtp-username-bo(24331)</ref>
      <ref url="http://www.securityfocus.com/bid/16379" source="BID">16379</ref>
      <ref url="http://www.osvdb.org/22763" source="OSVDB">22763</ref>
      <ref url="http://www.osvdb.org/22762" source="OSVDB">22762</ref>
      <ref url="http://www.osvdb.org/22761" source="OSVDB">22761</ref>
    </refs>
    <vuln_soft>
      <prod vendor="e-post_corporation" name="mail_server">
        <vers num="4.10"/>
        <vers num="enterprise_4.10"/>
      </prod>
      <prod vendor="e-post_corporation" name="smtp_server">
        <vers num="4.10"/>
        <vers num="enterprise_4.10"/>
      </prod>
      <prod vendor="e-post_corporation" name="spa-pro_mail_atsolomon">
        <vers num="4.00"/>
        <vers num="enterprise_4.00"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0448" published="2006-01-26" name="CVE-2006-0448" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in (1) EPSTIMAP4S.EXE and (2) SPA-IMAP4S.EXE in the IMAP service in E-Post Mail 4.05 and SPA-PRO Mail 4.05 allow remote attackers to (a) list arbitrary directories or cause a denial of service via the LIST command; or create arbitrary files via the (b) APPEND, (c) COPY, or (d) RENAME commands.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/secunia_research/2006-1/advisory/" source="MISC" patch="1" adv="1">http://secunia.com/secunia_research/2006-1/advisory/</ref>
      <ref url="http://secunia.com/advisories/18480" source="SECUNIA" patch="1" adv="1">18480</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24336" source="XF">epost--append-copy-rename-file-creation(24336)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0318" source="VUPEN">ADV-2006-0318</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24336" source="XF">epost--append-copy-rename-file-creation(24336)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24335" source="XF">epost-imap-list-directory-traversal(24335)</ref>
      <ref url="http://www.securityfocus.com/bid/16379" source="BID">16379</ref>
      <ref url="http://www.osvdb.org/22765" source="OSVDB">22765</ref>
      <ref url="http://www.osvdb.org/22764" source="OSVDB">22764</ref>
    </refs>
    <vuln_soft>
      <prod vendor="e-post_corporation" name="mail_server">
        <vers num="4.05"/>
      </prod>
      <prod vendor="e-post_corporation" name="spa-pro_mail_atsolomon">
        <vers num="4.05"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0449" published="2006-01-26" name="CVE-2006-0449" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Early termination vulnerability in the IMAP service in E-Post Mail 4.05 and SPA-PRO Mail 4.05 allows remote attackers to cause a denial of service (infinite loop) by sending an APPEND command and disconnecting before the expected amount of data is sent.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <design/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/secunia_research/2006-1/advisory/" source="MISC" patch="1" adv="1">http://secunia.com/secunia_research/2006-1/advisory/</ref>
      <ref url="http://secunia.com/advisories/18480" source="SECUNIA" patch="1" adv="1">18480</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0318" source="VUPEN">ADV-2006-0318</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24341" source="XF">epost-imap-append-dos(24341)</ref>
      <ref url="http://www.securityfocus.com/bid/16379" source="BID">16379</ref>
      <ref url="http://www.osvdb.org/22766" source="OSVDB">22766</ref>
    </refs>
    <vuln_soft>
      <prod vendor="e-post_corporation" name="mail_server">
        <vers num="4.05"/>
      </prod>
      <prod vendor="e-post_corporation" name="spa-pro_mail_atsolomon">
        <vers num="4.05"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0450" published="2006-01-26" name="CVE-2006-0450" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">phpBB 2.0.19 and earlier allows remote attackers to cause a denial of service (application crash) by (1) registering many users through profile.php or (2) using search.php to search in a certain way that confuses the database.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423030/100/0/threaded" source="BUGTRAQ" adv="1">20060125 HYSA-2006-001 phpBB 2.0.19 search.php and profile.php DOS Vulnerability</ref>
      <ref url="http://www.h4cky0u.org/advisories/HYSA-2006-001-phpbb.txt" source="MISC" adv="1">http://www.h4cky0u.org/advisories/HYSA-2006-001-phpbb.txt</ref>
      <ref url="http://h4cky0u.org/viewtopic.php?t=637" source="MISC">http://h4cky0u.org/viewtopic.php?t=637</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24327" source="XF">phpbb-search-profile-dos(24327)</ref>
      <ref url="http://securityreason.com/securityalert/368" source="SREASON">368</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbb_group" name="phpbb">
        <vers num="2.0.0"/>
        <vers num="2.0.1"/>
        <vers num="2.0.10"/>
        <vers num="2.0.11"/>
        <vers num="2.0.12"/>
        <vers num="2.0.13"/>
        <vers num="2.0.14"/>
        <vers num="2.0.15"/>
        <vers num="2.0.16"/>
        <vers num="2.0.17"/>
        <vers num="2.0.18"/>
        <vers num="2.0.19"/>
        <vers num="2.0.2"/>
        <vers num="2.0.3"/>
        <vers num="2.0.4"/>
        <vers num="2.0.5"/>
        <vers num="2.0.6"/>
        <vers num="2.0.6c"/>
        <vers num="2.0.6d"/>
        <vers num="2.0.7"/>
        <vers num="2.0.7a"/>
        <vers num="2.0.8"/>
        <vers num="2.0.8a"/>
        <vers num="2.0.9"/>
        <vers num="2.0_beta1"/>
        <vers num="2.0_rc1"/>
        <vers num="2.0_rc2"/>
        <vers num="2.0_rc3"/>
        <vers num="2.0_rc4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0451" published="2006-02-14" name="CVE-2006-0451" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple memory leaks in the LDAP component in Fedora Directory Server 1.0 allow remote attackers to cause a denial of service (memory consumption) via invalid BER packets that trigger an error, which might prevent memory from being freed if it was allocated during the ber_scanf call, as demonstrated using the ProtoVer LDAP test suite.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=179135" source="CONFIRM">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=179135</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24794" source="XF">fedora-ber-memory-leak-dos(24794)</ref>
      <ref url="http://www.securityfocus.com/bid/16677" source="BID">16677</ref>
      <ref url="http://secunia.com/advisories/18960" source="SECUNIA">18960</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="fedora_core">
        <vers num="1.0" edition=""/>
        <vers num="1.0" edition=":directory_server"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0452" published="2006-02-14" name="CVE-2006-0452" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">dn2ancestor in the LDAP component in Fedora Directory Server 1.0 allows remote attackers to cause a denial of service (CPU and memory consumption) via a ModDN operation with a DN that contains a large number of "," (comma) characters, which results in a large amount of recursion, as demonstrated using the ProtoVer LDAP test suite.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=179137" source="CONFIRM">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=179137</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24796" source="XF">fedora-dn2ancestor-dos(24796)</ref>
      <ref url="http://www.securityfocus.com/bid/16677" source="BID">16677</ref>
      <ref url="http://secunia.com/advisories/18960" source="SECUNIA">18960</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="fedora_core">
        <vers num="1.0" edition=""/>
        <vers num="1.0" edition=":directory_server"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0453" published="2006-02-14" name="CVE-2006-0453" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The LDAP component in Fedora Directory Server 1.0 allow remote attackers to cause a denial of service (crash) via a certain "bad BER sequence" that results in a free of uninitialized memory, as demonstrated using the ProtoVer LDAP test suite.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=179135" source="CONFIRM">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=179135</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24795" source="XF">fedora-ber-bad-sequence-dos(24795)</ref>
      <ref url="http://www.securityfocus.com/bid/16677" source="BID">16677</ref>
      <ref url="http://secunia.com/advisories/18960" source="SECUNIA">18960</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="fedora_core">
        <vers num="1.0" edition=""/>
        <vers num="1.0" edition=":directory_server"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0454" published="2006-02-07" name="CVE-2006-0454" modified="2012-03-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Linux kernel before 2.6.15.3 down to 2.6.12, while constructing an ICMP response in icmp_send, does not properly handle when the ip_options_echo function in icmp.c fails, which allows remote attackers to cause a denial of service (crash) via vectors such as (1) record-route and (2) timestamp IP options with the needaddr bit set and a truncated value.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16532" source="BID" patch="1">16532</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/427981/100/0/threaded" source="FEDORA" patch="1" adv="1">FLSA:157459-4</ref>
      <ref url="http://www.redhat.com/archives/fedora-announce-list/2006-February/msg00037.html" source="FEDORA" patch="1" adv="1">FEDORA-2006-102</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_06_kernel.html" source="SUSE" patch="1" adv="1">SUSE-SA:2006:006</ref>
      <ref url="http://secunia.com/advisories/18861" source="SECUNIA" patch="1" adv="1">18861</ref>
      <ref url="http://secunia.com/advisories/18788" source="SECUNIA" patch="1" adv="1">18788</ref>
      <ref url="http://secunia.com/advisories/18784" source="SECUNIA" patch="1" adv="1">18784</ref>
      <ref url="http://secunia.com/advisories/18774" source="SECUNIA" patch="1" adv="1">18774</ref>
      <ref url="http://secunia.com/advisories/18766" source="SECUNIA" patch="1" adv="1">18766</ref>
      <ref url="http://lists.immunitysec.com/pipermail/dailydave/2006-February/002909.html" source="MLIST" patch="1">[dailydave] 20060207 Fun with Linux (2.6.12 -> 2.6.15.2)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24575" source="XF">kernel-icmp-ipoptionsecho-dos(24575)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0464" source="VUPEN" adv="1">ADV-2006-0464</ref>
      <ref url="http://www.ubuntu.com/usn/usn-250-1" source="UBUNTU">USN-250-1</ref>
      <ref url="http://www.trustix.org/errata/2006/0006" source="TRUSTIX" adv="1">2006-0006</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:040" source="MANDRIVA">MDKSA-2006:040</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.15.3" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.15.3</ref>
      <ref url="http://marc.theaimsgroup.com/?l=linux-kernel&amp;m=113927648820694&amp;w=2" source="MLIST">[linux-kernel] 20060207 Re: Linux 2.6.15.3</ref>
      <ref url="http://marc.theaimsgroup.com/?l=linux-kernel&amp;m=113927617401569&amp;w=2" source="MLIST">[linux-kernel] 20060207 Linux 2.6.15.3</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.12" edition="rc1"/>
        <vers num="2.6.12" edition="rc2"/>
        <vers num="2.6.12" edition="rc3"/>
        <vers num="2.6.12" edition="rc4"/>
        <vers num="2.6.12" edition="rc5"/>
        <vers num="2.6.12" edition="rc6"/>
        <vers num="2.6.12.1"/>
        <vers num="2.6.12.2"/>
        <vers num="2.6.12.3"/>
        <vers num="2.6.12.4"/>
        <vers num="2.6.12.5"/>
        <vers num="2.6.12.6"/>
        <vers num="2.6.13" edition="rc1"/>
        <vers num="2.6.13" edition="rc2"/>
        <vers num="2.6.13" edition="rc3"/>
        <vers num="2.6.13" edition="rc4"/>
        <vers num="2.6.13" edition="rc5"/>
        <vers num="2.6.13" edition="rc6"/>
        <vers num="2.6.13" edition="rc7"/>
        <vers num="2.6.13.1"/>
        <vers num="2.6.13.2"/>
        <vers num="2.6.13.3"/>
        <vers num="2.6.13.4"/>
        <vers num="2.6.13.5"/>
        <vers num="2.6.14" edition="rc1"/>
        <vers num="2.6.14" edition="rc2"/>
        <vers num="2.6.14" edition="rc3"/>
        <vers num="2.6.14" edition="rc4"/>
        <vers num="2.6.14" edition="rc5"/>
        <vers num="2.6.14.1"/>
        <vers num="2.6.14.2"/>
        <vers num="2.6.14.3"/>
        <vers num="2.6.14.4"/>
        <vers num="2.6.14.5"/>
        <vers num="2.6.14.6"/>
        <vers num="2.6.14.7"/>
        <vers num="2.6.15"/>
        <vers num="2.6.15.1"/>
        <vers num="2.6.15.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0455" published="2006-02-15" name="CVE-2006-0455" modified="2011-10-18" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">gpgv in GnuPG before 1.4.2.1, when using unattended signature verification, returns a 0 exit code in certain cases even when the detached signature file does not carry a signature, which could cause programs that use gpgv to assume that the signature verification has succeeded.  Note: this also occurs when running the equivalent command "gpg --verify".</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <design/>
    </vuln_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.us.debian.org/security/2006/dsa-978" source="DEBIAN" patch="1" adv="1">DSA-978</ref>
      <ref url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2006&amp;m=slackware-security.476477" source="SLACKWARE" patch="1">SSA:2006-072-02</ref>
      <ref url="http://www.securityfocus.com/bid/16663" source="BID" patch="1">16663</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_09_gpg.html" source="SUSE" patch="1" adv="1">SUSE-SA:2006:009</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200602-10.xml" source="GENTOO" patch="1" adv="1">GLSA-200602-10</ref>
      <ref url="http://secunia.com/advisories/18968" source="SECUNIA" patch="1" adv="1">18968</ref>
      <ref url="http://secunia.com/advisories/18956" source="SECUNIA" patch="1" adv="1">18956</ref>
      <ref url="http://secunia.com/advisories/18955" source="SECUNIA" patch="1" adv="1">18955</ref>
      <ref url="http://secunia.com/advisories/18942" source="SECUNIA" patch="1" adv="1">18942</ref>
      <ref url="http://secunia.com/advisories/18934" source="SECUNIA" patch="1" adv="1">18934</ref>
      <ref url="http://secunia.com/advisories/18933" source="SECUNIA" patch="1" adv="1">18933</ref>
      <ref url="http://marc.theaimsgroup.com/?l=gnupg-devel&amp;m=113999098729114&amp;w=2" source="MLIST" patch="1" adv="1">[gnupg-devel] 20060215 [Announce] False positive signature verification in GnuPG</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24744" source="XF">gnupg-gpgv-improper-verification(24744)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0610" source="VUPEN" adv="1">ADV-2006-0610</ref>
      <ref url="http://www.ubuntu.com/usn/usn-252-1" source="UBUNTU">USN-252-1</ref>
      <ref url="http://www.trustix.org/errata/2006/0008" source="TRUSTIX">2006-0008</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/433931/100/0/threaded" source="FEDORA">FLSA-2006:185355</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/425289/100/0/threaded" source="BUGTRAQ">20060215 False positive signature verification in GnuPG</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0266.html" source="REDHAT">RHSA-2006:0266</ref>
      <ref url="http://www.osvdb.org/23221" source="OSVDB">23221</ref>
      <ref url="http://www.openpkg.org/security/OpenPKG-SA-2006.001-gnupg.html" source="OPENPKG" adv="1">OpenPKG-SA-2006.001</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_13_gpg.html" source="SUSE">SUSE-SA:2006:013</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006_05_sr.html" source="SUSE">SUSE-SR:2006:005</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:043" source="MANDRIVA">MDKSA-2006:043</ref>
      <ref url="http://secunia.com/advisories/19532" source="SECUNIA" adv="1">19532</ref>
      <ref url="http://secunia.com/advisories/19249" source="SECUNIA" adv="1">19249</ref>
      <ref url="http://secunia.com/advisories/19130" source="SECUNIA" adv="1">19130</ref>
      <ref url="http://secunia.com/advisories/18845" source="SECUNIA" adv="1">18845</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10084" source="OVAL">oval:org.mitre.oval:def:10084</ref>
      <ref url="http://lists.gnupg.org/pipermail/gnupg-announce/2006q1/000211.html" source="MLIST">[gnupg-announce] 20060215 False positive signature verification in GnuPG</ref>
      <ref url="http://fedoranews.org/updates/FEDORA-2006-116.shtml" source="FEDORA">FEDORA-2006-116</ref>
      <ref url="ftp://patches.sgi.com/support/free/security/advisories/20060401-01-U" source="SGI">20060401-01-U</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="privacy_guard">
        <vers num="1.0"/>
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0.3"/>
        <vers num="1.0.3b"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.2"/>
        <vers num="1.2.1"/>
        <vers num="1.2.2" edition="rc1"/>
        <vers num="1.2.3"/>
        <vers num="1.2.4"/>
        <vers num="1.2.5"/>
        <vers num="1.2.6"/>
        <vers num="1.2.7"/>
        <vers num="1.3.3"/>
        <vers num="1.3.4"/>
        <vers num="1.4"/>
        <vers num="1.4.1"/>
        <vers num="1.4.2"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2006-0456" published="2006-06-27" name="CVE-2006-0456" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The strnlen_user function in Linux kernel before 2.6.16 on IBM S/390 can return an incorrect value, which allows local users to cause a denial of service via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <range>
      <local/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/2554" source="VUPEN">ADV-2006-2554</ref>
      <ref url="http://www.mail-archive.com/kernel-svn-changes@lists.alioth.debian.org/msg01631.html" source="CONFIRM">http://www.mail-archive.com/kernel-svn-changes@lists.alioth.debian.org/msg01631.html</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.16-rc6" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.16-rc6</ref>
      <ref url="http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=331c46591414f7f92b1cec048009abe89892ee79" source="CONFIRM">http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=331c46591414f7f92b1cec048009abe89892ee79</ref>
      <ref url="http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=331c46591414f7f92b1cec048009abe89892ee79" source="CONFIRM">http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=331c46591414f7f92b1cec048009abe89892ee79</ref>
      <ref url="http://www.debian.org/security/2006/dsa-1103" source="DEBIAN">DSA-1103</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9909" source="OVAL">oval:org.mitre.oval:def:9909</ref>
      <ref url="http://www.securityfocus.com/bid/18687" source="BID">18687</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0575.html" source="REDHAT">RHSA-2006:0575</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-200.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-200.htm</ref>
      <ref url="http://secunia.com/advisories/22417" source="SECUNIA">22417</ref>
      <ref url="http://secunia.com/advisories/21465" source="SECUNIA">21465</ref>
      <ref url="http://secunia.com/advisories/20914" source="SECUNIA">20914</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0" edition="test1"/>
        <vers num="2.6.0" edition="test10"/>
        <vers num="2.6.0" edition="test11"/>
        <vers num="2.6.0" edition="test2"/>
        <vers num="2.6.0" edition="test3"/>
        <vers num="2.6.0" edition="test4"/>
        <vers num="2.6.0" edition="test5"/>
        <vers num="2.6.0" edition="test6"/>
        <vers num="2.6.0" edition="test7"/>
        <vers num="2.6.0" edition="test8"/>
        <vers num="2.6.0" edition="test9"/>
        <vers num="2.6.1" edition="rc1"/>
        <vers num="2.6.1" edition="rc2"/>
        <vers num="2.6.10" edition="rc1"/>
        <vers num="2.6.10" edition="rc2"/>
        <vers num="2.6.10" edition="rc3"/>
        <vers num="2.6.11" edition="rc1"/>
        <vers num="2.6.11" edition="rc2"/>
        <vers num="2.6.11" edition="rc3"/>
        <vers num="2.6.11" edition="rc4"/>
        <vers num="2.6.11" edition="rc5"/>
        <vers num="2.6.11.11"/>
        <vers num="2.6.11.12"/>
        <vers num="2.6.11.5"/>
        <vers num="2.6.11.6"/>
        <vers num="2.6.11.7"/>
        <vers num="2.6.11.8"/>
        <vers num="2.6.12" edition="rc1"/>
        <vers num="2.6.12" edition="rc2"/>
        <vers num="2.6.12" edition="rc3"/>
        <vers num="2.6.12" edition="rc4"/>
        <vers num="2.6.12" edition="rc5"/>
        <vers num="2.6.12" edition="rc6"/>
        <vers num="2.6.12.1"/>
        <vers num="2.6.12.2"/>
        <vers num="2.6.12.3"/>
        <vers num="2.6.12.4"/>
        <vers num="2.6.12.5"/>
        <vers num="2.6.12.6"/>
        <vers num="2.6.13" edition="rc1"/>
        <vers num="2.6.13" edition="rc2"/>
        <vers num="2.6.13" edition="rc3"/>
        <vers num="2.6.13" edition="rc4"/>
        <vers num="2.6.13" edition="rc5"/>
        <vers num="2.6.13" edition="rc6"/>
        <vers num="2.6.13" edition="rc7"/>
        <vers num="2.6.13.1"/>
        <vers num="2.6.13.2"/>
        <vers num="2.6.13.3"/>
        <vers num="2.6.13.4"/>
        <vers num="2.6.14" edition="rc1"/>
        <vers num="2.6.14" edition="rc2"/>
        <vers num="2.6.14" edition="rc3"/>
        <vers num="2.6.14" edition="rc4"/>
        <vers num="2.6.14" edition="rc5"/>
        <vers num="2.6.14.1"/>
        <vers num="2.6.14.2"/>
        <vers num="2.6.14.3"/>
        <vers num="2.6.14.4"/>
        <vers num="2.6.14.5"/>
        <vers num="2.6.15" edition="rc1"/>
        <vers num="2.6.15" edition="rc3"/>
        <vers num="2.6.15" edition="rc4"/>
        <vers num="2.6.15" edition="rc5"/>
        <vers num="2.6.15" edition="rc6"/>
        <vers num="2.6.15" edition="rc7"/>
        <vers num="2.6.15.1"/>
        <vers num="2.6.15.2"/>
        <vers num="2.6.15.3"/>
        <vers num="2.6.15.4"/>
        <vers num="2.6.15.5"/>
        <vers num="2.6.2" edition="rc1"/>
        <vers num="2.6.2" edition="rc2"/>
        <vers num="2.6.2" edition="rc3"/>
        <vers num="2.6.3" edition="rc1"/>
        <vers num="2.6.3" edition="rc2"/>
        <vers num="2.6.3" edition="rc3"/>
        <vers num="2.6.4" edition="rc1"/>
        <vers num="2.6.4" edition="rc2"/>
        <vers num="2.6.4" edition="rc3"/>
        <vers num="2.6.5" edition="rc1"/>
        <vers num="2.6.5" edition="rc2"/>
        <vers num="2.6.5" edition="rc3"/>
        <vers num="2.6.6" edition="rc1"/>
        <vers num="2.6.6" edition="rc2"/>
        <vers num="2.6.6" edition="rc3"/>
        <vers num="2.6.7" edition="rc1"/>
        <vers num="2.6.7" edition="rc2"/>
        <vers num="2.6.7" edition="rc3"/>
        <vers num="2.6.8" edition="rc1"/>
        <vers num="2.6.8" edition="rc2"/>
        <vers num="2.6.8" edition="rc3"/>
        <vers num="2.6.8" edition="rc4"/>
        <vers num="2.6.9" edition="2.6.20"/>
        <vers num="2.6.9" edition="rc1"/>
        <vers num="2.6.9" edition="rc2"/>
        <vers num="2.6.9" edition="rc3"/>
        <vers num="2.6.9" edition="rc4"/>
        <vers num="2.6_test9_cvs"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0457" published="2006-03-13" name="CVE-2006-0457" modified="2010-08-21" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="9.2" CVSS_exploit_subscore="4.9" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">Race condition in the (1) add_key, (2) request_key, and (3) keyctl functions in Linux kernel 2.6.x allows local users to cause a denial of service (crash) or read sensitive kernel memory by modifying the length of a string argument between the time that the kernel calculates the length and when it copies the data into kernel memory.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
    </loss_types>
    <vuln_types>
      <race/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-263-1" source="UBUNTU" adv="1">USN-263-1</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9566" source="OVAL">oval:org.mitre.oval:def:9566</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25354" source="XF">kernel-addkey-dos(25354)</ref>
      <ref url="http://www.securityfocus.com/bid/17084" source="BID">17084</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2006-0575.html" source="REDHAT">RHSA-2006:0575</ref>
      <ref url="http://www.osvdb.org/23894" source="OSVDB">23894</ref>
      <ref url="http://www.novell.com/linux/security/advisories/2006-05-31.html" source="SUSE">SUSE-SA:2006:028</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDKSA-2006:059" source="MANDRIVA">MDKSA-2006:059</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2006-200.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2006-200.htm</ref>
      <ref url="http://secunia.com/advisories/22417" source="SECUNIA">22417</ref>
      <ref url="http://secunia.com/advisories/21465" source="SECUNIA">21465</ref>
      <ref url="http://secunia.com/advisories/20398" source="SECUNIA">20398</ref>
      <ref url="http://secunia.com/advisories/19220" source="SECUNIA">19220</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.6.0" edition="test1"/>
        <vers num="2.6.0" edition="test10"/>
        <vers num="2.6.0" edition="test11"/>
        <vers num="2.6.0" edition="test2"/>
        <vers num="2.6.0" edition="test3"/>
        <vers num="2.6.0" edition="test4"/>
        <vers num="2.6.0" edition="test5"/>
        <vers num="2.6.0" edition="test6"/>
        <vers num="2.6.0" edition="test7"/>
        <vers num="2.6.0" edition="test8"/>
        <vers num="2.6.0" edition="test9"/>
        <vers num="2.6.1" edition="rc1"/>
        <vers num="2.6.1" edition="rc2"/>
        <vers num="2.6.10" edition="rc2"/>
        <vers num="2.6.11" edition="rc1"/>
        <vers num="2.6.11" edition="rc2"/>
        <vers num="2.6.11" edition="rc3"/>
        <vers num="2.6.11" edition="rc4"/>
        <vers num="2.6.11.1"/>
        <vers num="2.6.11.10"/>
        <vers num="2.6.11.11"/>
        <vers num="2.6.11.12"/>
        <vers num="2.6.11.2"/>
        <vers num="2.6.11.3"/>
        <vers num="2.6.11.4"/>
        <vers num="2.6.11.5"/>
        <vers num="2.6.11.6"/>
        <vers num="2.6.11.7"/>
        <vers num="2.6.11.8"/>
        <vers num="2.6.11.9"/>
        <vers num="2.6.11_rc1_bk6"/>
        <vers num="2.6.12" edition="rc1"/>
        <vers num="2.6.12" edition="rc4"/>
        <vers num="2.6.12" edition="rc5"/>
        <vers num="2.6.12.1"/>
        <vers num="2.6.12.2"/>
        <vers num="2.6.12.3"/>
        <vers num="2.6.12.4"/>
        <vers num="2.6.12.5"/>
        <vers num="2.6.12.6"/>
        <vers num="2.6.13" edition="rc1"/>
        <vers num="2.6.13" edition="rc4"/>
        <vers num="2.6.13" edition="rc6"/>
        <vers num="2.6.13" edition="rc7"/>
        <vers num="2.6.13.1"/>
        <vers num="2.6.13.2"/>
        <vers num="2.6.13.3"/>
        <vers num="2.6.13.4"/>
        <vers num="2.6.14" edition="rc1"/>
        <vers num="2.6.14" edition="rc2"/>
        <vers num="2.6.14" edition="rc3"/>
        <vers num="2.6.14" edition="rc4"/>
        <vers num="2.6.14.1"/>
        <vers num="2.6.14.2"/>
        <vers num="2.6.14.3"/>
        <vers num="2.6.14.4"/>
        <vers num="2.6.15" edition="rc1"/>
        <vers num="2.6.15" edition="rc3"/>
        <vers num="2.6.15" edition="rc4"/>
        <vers num="2.6.15" edition="rc5"/>
        <vers num="2.6.15" edition="rc6"/>
        <vers num="2.6.15" edition="rc7"/>
        <vers num="2.6.15.1"/>
        <vers num="2.6.15.2"/>
        <vers num="2.6.15.3"/>
        <vers num="2.6.15.4"/>
        <vers num="2.6.15.5"/>
        <vers num="2.6.3"/>
        <vers num="2.6.4"/>
        <vers num="2.6.5"/>
        <vers num="2.6.6" edition="rc1"/>
        <vers num="2.6.7" edition="rc1"/>
        <vers num="2.6.8" edition="rc1"/>
        <vers num="2.6.8" edition="rc2"/>
        <vers num="2.6.8" edition="rc3"/>
        <vers num="2.6.8.1"/>
        <vers num="2.6.8.1.5"/>
        <vers num="2.6.9" edition="2.6.20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0458" published="2006-03-06" name="CVE-2006-0458" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The DCC ACCEPT command handler in irssi before 0.8.9+0.8.10rc5-0ubuntu4.1 in Ubuntu Linux, and possibly other distributions, allows remote attackers to cause a denial of service (application crash) via certain crafted arguments in a DCC command.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/19090" source="SECUNIA" patch="1" adv="1">19090</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-259-1" source="UBUNTU" adv="1">USN-259-1</ref>
      <ref url="http://www.securityfocus.com/bid/16913" source="BID">16913</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25147" source="XF">irssi-dcc-accept-dos(25147)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="irssi" name="irssi">
        <vers num="0.8.10rc5"/>
        <vers num="0.8.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0459" published="2006-03-29" name="CVE-2006-0459" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">flex.skl in Will Estes and John Millaway Fast Lexical Analyzer Generator (flex) before 2.5.33 does not allocate enough memory for grammars containing (1) REJECT statements or (2) trailing context rules, which causes flex to generate code that contains a buffer overflow that might allow context-dependent attackers to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24995" source="XF" patch="1">flex-bypass-security(24995)</ref>
      <ref url="http://www.us.debian.org/security/2006/dsa-1020" source="DEBIAN" patch="1" adv="1">DSA-1020</ref>
      <ref url="http://www.securityfocus.com/bid/16896" source="BID" patch="1">16896</ref>
      <ref url="http://www.osvdb.org/23440" source="OSVDB" patch="1">23440</ref>
      <ref url="http://secunia.com/advisories/19424" source="SECUNIA" patch="1" adv="1">19424</ref>
      <ref url="http://secunia.com/advisories/19071" source="SECUNIA" patch="1" adv="1">19071</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0770" source="VUPEN">ADV-2006-0770</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-260-1" source="UBUNTU">USN-260-1</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200603-07.xml" source="GENTOO">GLSA-200603-07</ref>
      <ref url="http://sourceforge.net/mailarchive/forum.php?thread_name=20060223020346.GA11231%40tabitha.home.tldz.org&amp;forum_name=flex-announce" source="MLIST">[flex-announce] 20060222 flex 2.5.33 released</ref>
      <ref url="http://securityreason.com/securityalert/570" source="SREASON">570</ref>
      <ref url="http://secunia.com/advisories/19228" source="SECUNIA" adv="1">19228</ref>
      <ref url="http://secunia.com/advisories/19126" source="SECUNIA" adv="1">19126</ref>
      <ref url="http://prdownloads.sourceforge.net/flex/flex-2.5.33.tar.bz2?download" source="CONFIRM">http://prdownloads.sourceforge.net/flex/flex-2.5.33.tar.bz2?download</ref>
    </refs>
    <vuln_soft>
      <prod vendor="will_estes_and_john_millaway" name="flex">
        <vers num="2.5.30"/>
        <vers prev="1" num="2.5.32"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0460" published="2006-02-16" name="CVE-2006-0460" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in BomberClone before 0.11.6.2 allow remote attackers to execute arbitrary code via long error messages.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200602-09.xml" source="GENTOO" patch="1" adv="1">GLSA-200602-09</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0643" source="VUPEN">ADV-2006-0643</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24764" source="XF">bomberclone-error-message-bo(24764)</ref>
      <ref url="http://www.securityfocus.com/bid/16697" source="BID">16697</ref>
      <ref url="http://www.osvdb.org/23263" source="OSVDB">23263</ref>
      <ref url="http://www.debian.org/security/2006/dsa-997" source="DEBIAN">DSA-997</ref>
      <ref url="http://secunia.com/advisories/19210" source="SECUNIA">19210</ref>
      <ref url="http://secunia.com/advisories/18915" source="SECUNIA">18915</ref>
      <ref url="http://secunia.com/advisories/18914" source="SECUNIA">18914</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bomberclone" name="bomberclone">
        <vers num="0.1"/>
        <vers num="0.10.0"/>
        <vers num="0.11.3"/>
        <vers num="0.11.4"/>
        <vers num="0.11.5"/>
        <vers num="0.11.6"/>
        <vers num="0.2"/>
        <vers num="0.3"/>
        <vers num="0.4"/>
        <vers num="0.5"/>
        <vers num="0.6"/>
        <vers num="0.7"/>
        <vers num="0.8"/>
        <vers num="0.9.5"/>
        <vers num="0.9.6"/>
        <vers num="0.9.7"/>
        <vers num="0.9.8"/>
        <vers num="0.9.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0461" published="2006-01-27" name="CVE-2006-0461" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in core.input.php in ExpressionEngine 1.4.1 allows remote attackers to inject arbitrary web script or HTML via HTTP_REFERER (referer).</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://evuln.com/vulns/48/summary.html" source="MISC" patch="1" adv="1">http://evuln.com/vulns/48/summary.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0325" source="VUPEN">ADV-2006-0325</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24296" source="XF">expressionengine-coreinput-xss(24296)</ref>
      <ref url="http://www.securityfocus.com/bid/16377" source="BID">16377</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423068/100/0/threaded" source="BUGTRAQ">20060125 [eVuln] ExpressionEngine 'Referer' XSS Vulnerability</ref>
      <ref url="http://securityreason.com/securityalert/372" source="SREASON">372</ref>
      <ref url="http://secunia.com/advisories/18602" source="SECUNIA">18602</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pmachine" name="expressionengine">
        <vers num="1.4.1"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0462" published="2006-01-27" name="CVE-2006-0462" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in comentarios.php in AndoNET Blog 2004.09.02 allows remote attackers to execute arbitrary SQL commands via the entrada parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0327" source="VUPEN">ADV-2006-0327</ref>
      <ref url="http://evuln.com/vulns/50/summary.html" source="MISC" adv="1">http://evuln.com/vulns/50/summary.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24309" source="XF">andonetblog-index-sql-injection(24309)</ref>
      <ref url="http://www.securityfocus.com/bid/16393" source="BID">16393</ref>
      <ref url="http://www.securityfocus.com/archive/1/423162" source="BUGTRAQ">20060126 [eVuln] AndoNET Blog SQL Injection Vulnerability</ref>
      <ref url="http://www.osvdb.org/22755" source="OSVDB">22755</ref>
      <ref url="http://securityreason.com/securityalert/377" source="SREASON">377</ref>
      <ref url="http://secunia.com/advisories/18633" source="SECUNIA">18633</ref>
    </refs>
    <vuln_soft>
      <prod vendor="andonet" name="andonet_blog">
        <vers num="2004.09.02"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0463" published="2006-01-27" name="CVE-2006-0463" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in IdeoContent Manager allows remote attackers to inject arbitrary web script or HTML via the (1) goto_id parameter to index.php or (2) page parameter to news_full.php.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.osvdb.org/22713" source="OSVDB">22713</ref>
      <ref url="http://www.osvdb.org/22712" source="OSVDB">22712</ref>
      <ref url="http://osvdb.org/ref/22/22712-ideocontent.txt" source="MISC">http://osvdb.org/ref/22/22712-ideocontent.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ideosoft_design" name="ideocontent_manager">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0464" published="2006-01-27" name="CVE-2006-0464" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in index.php in IdeoContent Manager allow remote attackers to execute arbitrary SQL commands via the (1) goto_id or (2) mid parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.osvdb.org/22714" source="OSVDB">22714</ref>
      <ref url="http://osvdb.org/ref/22/22712-ideocontent.txt" source="MISC">http://osvdb.org/ref/22/22712-ideocontent.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ideosoft_design" name="ideocontent_manager">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0465" published="2006-01-27" name="CVE-2006-0465" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in risultati_ricerca.php in active121 Site Manager allows remote attackers to inject arbitrary web script or HTML via the cerca parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.osvdb.org/22715" source="OSVDB">22715</ref>
      <ref url="http://osvdb.org/ref/22/22715-active121.txt" source="MISC">http://osvdb.org/ref/22/22715-active121.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="active121" name="site_manager">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0466" published="2006-01-27" name="CVE-2006-0466" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in search.asp in Goldstag Content Management System allows remote attackers to inject arbitrary web script or HTML via the text parameter.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.osvdb.org/22711" source="OSVDB">22711</ref>
      <ref url="http://osvdb.org/ref/22/22711-goldstag.txt" source="MISC">http://osvdb.org/ref/22/22711-goldstag.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/25198" source="XF">goldstag-search-xss(25198)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="goldstag" name="goldstag_content_management_system">
        <vers num=""/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0467" published="2006-01-30" name="CVE-2006-0467" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Pioneers (formerly gnocatan) before 0.9.49 allows remote attackers to cause a denial of service (application crash) via long chat messages.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <input bound="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24383" source="XF" patch="1">pioneers-chat-message-dos(24383)</ref>
      <ref url="http://www.debian.org/security/2006/dsa-964" source="DEBIAN" patch="1" adv="1">DSA-964</ref>
      <ref url="http://secunia.com/advisories/18692" source="SECUNIA" patch="1" adv="1">18692</ref>
      <ref url="http://secunia.com/advisories/18647" source="SECUNIA" patch="1" adv="1">18647</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0376" source="VUPEN" adv="1">ADV-2006-0376</ref>
      <ref url="http://www.securityfocus.com/bid/16429" source="BID">16429</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=350237" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=350237</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pioneers" name="pioneers">
        <vers num="0.9.49"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0468" published="2006-01-30" name="CVE-2006-0468" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">CommuniGate Pro Core Server before 5.0.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via LDAP messages with negative BER lengths, and possibly other vectors, as demonstrated by the ProtoVer LDAP test suite.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16407" source="BID" patch="1">16407</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423364/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20060128 Multiple vulnerabilities in CommuniGate Pro Server</ref>
      <ref url="http://www.gleg.net/advisory_cg.shtml" source="MISC" patch="1" adv="1">http://www.gleg.net/advisory_cg.shtml</ref>
      <ref url="http://secunia.com/advisories/18640" source="SECUNIA" patch="1" adv="1">18640</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0364" source="VUPEN">ADV-2006-0364</ref>
      <ref url="http://www.stalker.com/CommuniGatePro/History.html" source="CONFIRM">http://www.stalker.com/CommuniGatePro/History.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24409" source="XF">communigate-ldap-bo(24409)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="stalker" name="communigate_pro">
        <vers num="5.0"/>
        <vers num="5.0.1"/>
        <vers num="5.0.2"/>
        <vers num="5.0.3"/>
        <vers num="5.0.4"/>
        <vers num="5.0.5"/>
        <vers num="5.0.6"/>
        <vers num="5.0c1"/>
        <vers num="5.0c2"/>
        <vers num="5.0c3"/>
        <vers num="5.0c4"/>
        <vers num="5.0c5"/>
        <vers num="5.0c6"/>
        <vers num="5.0c7"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0469" published="2006-01-30" name="CVE-2006-0469" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in UebiMiau 2.7.9, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via a javascript: URI in the SRC attribute of an IMG tag.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24375" source="XF">uebimiau-html-xss(24375)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0388" source="VUPEN">ADV-2006-0388</ref>
      <ref url="http://www.uebimiau.org/news.php" source="CONFIRM">http://www.uebimiau.org/news.php</ref>
      <ref url="http://www.securityfocus.com/bid/16413" source="BID">16413</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423437/100/0/threaded" source="BUGTRAQ">20060129 UebiMiau Webmail System Security Vulnerability</ref>
      <ref url="http://secunia.com/advisories/18655" source="SECUNIA">18655</ref>
      <ref url="http://securityreason.com/securityalert/387" source="SREASON">387</ref>
    </refs>
    <vuln_soft>
      <prod vendor="uebimiau" name="uebimiau">
        <vers num="2.7.9"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0470" published="2006-01-31" name="CVE-2006-0470" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in search.php in MyBulletinBoard (MyBB) 1.02 allows remote attackers to inject arbitrary web script or HTML via the (1) sortby and (2) sortordr parameters, which are not properly handled in a redirection.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0350" source="VUPEN">ADV-2006-0350</ref>
      <ref url="http://www.securityfocus.com/bid/16387" source="BID">16387</ref>
      <ref url="http://www.osvdb.org/22750" source="OSVDB">22750</ref>
      <ref url="http://secunia.com/advisories/18617" source="SECUNIA" adv="1">18617</ref>
      <ref url="http://seclists.org/lists/bugtraq/2006/Jan/0414.html" source="BUGTRAQ" adv="1">20060125 MyBB 1.0.2 XSS attack in search.php redirection</ref>
      <ref url="http://community.mybboard.net/showthread.php?tid=6418" source="CONFIRM">http://community.mybboard.net/showthread.php?tid=6418</ref>
      <ref url="http://community.mybboard.net/attachment.php?aid=2181" source="CONFIRM">http://community.mybboard.net/attachment.php?aid=2181</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24466" source="XF">mybb-search-xss(24466)</ref>
      <ref url="http://securityreason.com/securityalert/374" source="SREASON">374</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mybulletinboard" name="mybulletinboard">
        <vers num="1.0.1"/>
        <vers num="1.0.2"/>
        <vers num="1.0_final"/>
        <vers num="1.0_pr2"/>
        <vers num="1.0_preview_release_2"/>
        <vers num="1.0_rc2"/>
        <vers num="1.0_rc4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0471" published="2006-01-31" name="CVE-2006-0471" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the bbcode function in functions.php in my little homepage my little forum, as last modified in June 2005, allows remote attackers to inject arbitrary Javascript via a javascript URI in BBcode link tags.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24310" source="XF">mylittlehomepage-link-tag-xss(24310)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0349" source="VUPEN">ADV-2006-0349</ref>
      <ref url="http://www.securityfocus.com/bid/16395" source="BID">16395</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423167/100/0/threaded" source="BUGTRAQ" adv="1">20060126 [eVuln] "my little homepage" products [link] BBCode XSS Vulnerability</ref>
      <ref url="http://secunia.com/advisories/18628" source="SECUNIA" adv="1">18628</ref>
      <ref url="http://evuln.com/vulns/51/summary.html" source="MISC" adv="1">http://evuln.com/vulns/51/summary.html</ref>
      <ref url="http://www.osvdb.org/22856" source="OSVDB">22856</ref>
      <ref url="http://evuln.com/vulns/51/" source="MISC">http://evuln.com/vulns/51/</ref>
      <ref url="http://attrition.org/pipermail/vim/2006-January/000520.html" source="VIM">20060130 My Little Homepage - source verify of different products</ref>
    </refs>
    <vuln_soft>
      <prod vendor="my_little_homepage" name="my_little_forum">
        <vers num="2004-04-20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0472" published="2006-01-31" name="CVE-2006-0472" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in guestbook.php in my little homepage my little guestbook, as last modified in March 2004, allows remote attackers to inject arbitrary Javascript via a javascript URI in BBcode link tags.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24310" source="XF">mylittlehomepage-link-tag-xss(24310)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0349" source="VUPEN">ADV-2006-0349</ref>
      <ref url="http://www.securityfocus.com/bid/16395" source="BID">16395</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423167/100/0/threaded" source="BUGTRAQ" adv="1">20060126 [eVuln] "my little homepage" products [link] BBCode XSS Vulnerability</ref>
      <ref url="http://secunia.com/advisories/18628" source="SECUNIA" adv="1">18628</ref>
      <ref url="http://evuln.com/vulns/51/summary.html" source="MISC" adv="1">http://evuln.com/vulns/51/summary.html</ref>
      <ref url="http://www.osvdb.org/22855" source="OSVDB">22855</ref>
      <ref url="http://evuln.com/vulns/51/" source="MISC">http://evuln.com/vulns/51/</ref>
      <ref url="http://attrition.org/pipermail/vim/2006-January/000520.html" source="VIM">20060130 My Little Homepage - source verify of different products</ref>
    </refs>
    <vuln_soft>
      <prod vendor="my_little_homepage" name="my_little_guestbook">
        <vers num="2004-04-20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0473" published="2006-01-31" name="CVE-2006-0473" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the bbcode function in weblog.php in my little homepage my little weblog, as last modified in April 2004, allows remote attackers to inject arbitrary Javascript via a javascript URI in BBcode link tags.</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24310" source="XF">mylittlehomepage-link-tag-xss(24310)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0349" source="VUPEN">ADV-2006-0349</ref>
      <ref url="http://www.securityfocus.com/bid/16395" source="BID">16395</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423167/100/0/threaded" source="BUGTRAQ" adv="1">20060126 [eVuln] "my little homepage" products [link] BBCode XSS Vulnerability</ref>
      <ref url="http://secunia.com/advisories/18628" source="SECUNIA" adv="1">18628</ref>
      <ref url="http://evuln.com/vulns/51/summary.html" source="MISC" adv="1">http://evuln.com/vulns/51/summary.html</ref>
      <ref url="http://www.osvdb.org/22753" source="OSVDB">22753</ref>
      <ref url="http://securityreason.com/securityalert/378" source="SREASON">378</ref>
      <ref url="http://evuln.com/vulns/51/" source="MISC">http://evuln.com/vulns/51/</ref>
      <ref url="http://attrition.org/pipermail/vim/2006-January/000520.html" source="VIM">20060130 My Little Homepage - source verify of different products</ref>
    </refs>
    <vuln_soft>
      <prod vendor="my_little_homepage" name="my_little_weblog">
        <vers num="2004-04-20"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0474" published="2006-01-31" name="CVE-2006-0474" modified="2008-09-05" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple integer overflows in Shareaza 2.2.1.0 allow remote attackers to execute arbitrary code via (1) a large packet length field, which causes an overflow in the ReadBuffer function in (a) BTPacket.cpp and (b) EDPacket.cpp, or (2) a large packet, which causes a heap-based overflow in the Write function in (c) Packet.h.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16399" source="BID">16399</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423293/100/0/threaded" source="BUGTRAQ" adv="1">20060127 Shareaza P2P Remote Vulnerability</ref>
      <ref url="http://www.hustlelabs.com/shareaza_advisory.pdf" source="MISC" adv="1">http://www.hustlelabs.com/shareaza_advisory.pdf</ref>
      <ref url="http://cvs.sourceforge.net/viewcvs.py/shareaza/shareaza/EDPacket.cpp?r1=1.15&amp;r2=1.15.2.1" source="CONFIRM">http://cvs.sourceforge.net/viewcvs.py/shareaza/shareaza/EDPacket.cpp?r1=1.15&amp;r2=1.15.2.1</ref>
      <ref url="http://cvs.sourceforge.net/viewcvs.py/shareaza/shareaza/BTPacket.cpp?r1=1.5&amp;r2=1.5.4.1" source="CONFIRM">http://cvs.sourceforge.net/viewcvs.py/shareaza/shareaza/BTPacket.cpp?r1=1.5&amp;r2=1.5.4.1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24344" source="XF">shareaza-cpacket-bo(24344)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24343" source="XF">shareaza-cedpacket-bo(24343)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24342" source="XF">shareaza-btpacket-bo(24342)</ref>
      <ref url="http://securityreason.com/securityalert/382" source="SREASON">382</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0887.html" source="FULLDISC">20060126 Shareaza Remote Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="shareaza" name="shareaza">
        <vers num="2.2.1.0"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0475" published="2006-01-31" name="CVE-2006-0475" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PHP-Ping 1.3 does not properly validate ping counts, which allows remote attackers to cause a denial of service (ping flood) via a negative count parameter.</descript>
    </desc>
    <loss_types>
      <avail/>
    </loss_types>
    <vuln_types>
      <design/>
      <exception/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2006/0368" source="VUPEN">ADV-2006-0368</ref>
      <ref url="http://www.kapda.ir/advisory-231.html" source="MISC">http://www.kapda.ir/advisory-231.html</ref>
      <ref url="http://secunia.com/advisories/18645" source="SECUNIA" adv="1">18645</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24382" source="XF">phpping-negative-count-dos(24382)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="theworldsend.net" name="php-ping">
        <vers num="1.3"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0476" published="2006-01-31" name="CVE-2006-0476" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Buffer overflow in Nullsoft Winamp 5.12 allows remote attackers to execute arbitrary code via a playlist (pls) file with a long file name (File1 field).</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot admin="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
      <user_init/>
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA06-032A.html" source="CERT">TA06-032A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/604745" source="CERT-VN">VU#604745</ref>
      <ref url="http://secunia.com/advisories/18649" source="SECUNIA" patch="1" adv="1">18649</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24361" source="XF">winamp-playlist-filename-bo(24361)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24361" source="XF">winamp-playlist-filename-bo(24361)</ref>
      <ref url="http://www.winamp.com/player/version_history.php" source="MISC">http://www.winamp.com/player/version_history.php</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0361" source="VUPEN">ADV-2006-0361</ref>
      <ref url="http://www.securityfocus.com/bid/16410" source="BID">16410</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/423548/100/0/threaded" source="BUGTRAQ">20060131 Re: Re: Winamp 5.12 - 0day exploit - code execution through playlist</ref>
      <ref url="http://www.securityfocus.com/archive/1/423436/100/0/threaded" source="BUGTRAQ">20060130 Winamp 5.12 - 0day exploit - code execution through playlist</ref>
      <ref url="http://www.osvdb.org/22789" source="OSVDB">22789</ref>
      <ref url="http://www.heise.de/newsticker/meldung/68981" source="MISC">http://www.heise.de/newsticker/meldung/68981</ref>
      <ref url="http://securitytracker.com/id?1015552" source="SECTRACK">1015552</ref>
      <ref url="http://www.milw0rm.com/exploits/3422" source="MILW0RM">3422</ref>
      <ref url="http://securityreason.com/securityalert/398" source="SREASON">398</ref>
      <ref url="http://securityreason.com/securityalert/386" source="SREASON">386</ref>
      <ref url="http://milw0rm.com/exploits/1458" source="MILW0RM">1458</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1402" source="OVAL" sig="1">oval:org.mitre.oval:def:1402</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nullsoft" name="winamp">
        <vers num="5.12"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0477" published="2006-01-31" name="CVE-2006-0477" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in git-checkout-index in GIT before 1.1.5 allows remote attackers to execute arbitrary code via an index file with a long symbolic link.</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot user="1"/>
    </loss_types>
    <vuln_types>
      <input buffer="1"/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/18643" source="SECUNIA" patch="1" adv="1">18643</ref>
      <ref url="http://lwn.net/Articles/169623/" source="CONFIRM" patch="1">http://lwn.net/Articles/169623/</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0367" source="VUPEN">ADV-2006-0367</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24360" source="XF">git-gitcheckoutindex-bo(24360)</ref>
      <ref url="http://www.securityfocus.com/bid/16417" source="BID">16417</ref>
    </refs>
    <vuln_soft>
      <prod vendor="git" name="git">
        <vers num="1.0.0"/>
        <vers num="1.0.0b"/>
        <vers num="1.0.3"/>
        <vers num="1.0.4"/>
        <vers num="1.0.5"/>
        <vers num="1.0.6"/>
        <vers num="1.0.7"/>
        <vers num="1.0.8"/>
        <vers num="1.1.0"/>
        <vers num="1.1.1"/>
        <vers num="1.1.2"/>
        <vers num="1.1.3"/>
        <vers num="1.1.4"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2006-0478" published="2006-01-31" name="CVE-2006-0478" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">CRE Loaded 6.15 allows remote attackers to perform privileged actions, including uploading and creating arbitrary files, via a direct request to files.php.  NOTE: the vendor states "The initial announcement of this risk was made on our website... and it included a patch which will close the vulnerability on all known 6.0x and 6.1x releases.  We strongly encourage users of CRE Loaded 6.x, osCMax, and other users of osCommerce who have installed HTMLArea based WYSIWYG editors and Admin Access with Levels to modify thier installations at the earliest possible moment."</descript>
    </desc>
    <loss_types>
      <avail/>
      <conf/>
      <int/>
      <sec_prot other="1"/>
    </loss_types>
    <vuln_types>
      <input/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/16415" source="BID" patch="1">16415</ref>
      <ref url="http://secunia.com/advisories/18648" source="SECUNIA" patch="1" adv="1">18648</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24377" source="XF">creloaded-files-auth-bypass(24377)</ref>
      <ref url="http://www.vupen.com/english/advisories/2006/0373" source="VUPEN">ADV-2006-0373</ref>
      <ref url="http://www.osvdb.org/22793" source="OSVDB">22793</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2006-February/000527.html" source="VIM">20060203 vendor ack/fix: 22793: CRE Loaded files.php Unauthenticated Arbitrary File Upload (fwd)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cre_loaded" name="cre_loaded">
        <vers num="6.15"/>
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2006-0479" published="2006-01-31" name="CVE-2006-0479" modified="2011-03-07" CVSS_version="2.0 upgrade from v1.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">pmwiki.php in PmWiki 2.1 beta 20, with register_globals enabled, allows remote attackers to bypass protection mechanisms that deregister global variables by setting both a GPC variable and a GLOBALS[] variable with the same name, which causes PmWiki to unset the GLOBALS[] variable but not the GPC variable, which creates resultant vulnerabilities such as remote file inclusion and cross-site scripting (XSS).</descript>
    </desc>
    <loss_types>
      <int/>
    </loss_types>
    <vuln_types>
      <config/>
    </vuln_types>
    <range>
      <network/>
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/24368" source="XF">pmwiki-multiple-xss(24368)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24367" source="XF">pmwiki-file-include(24367)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/24366" source="XF">pmwiki-path-